JDK: Insecure RPATH in multiple binaries on AIX
Published Aug 5, 2019
7.8
HIGHCVSS 3.1
EPSS 0.45%
Description
Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984.
Affected products
-
Affected
- 7
- 7R1
- 8
No data.
Red Hat Enterprise Linux 6
java-1.7.1-ibm
Not affected
Red Hat Enterprise Linux 6
java-1.8.0-ibm
Not affected
Red Hat Enterprise Linux 7
java-1.7.1-ibm
Not affected
Red Hat Enterprise Linux 7
java-1.8.0-ibm
Not affected
Red Hat Enterprise Linux 8
java-1.8.0-ibm
Not affected
Red Hat Satellite 5
java-1.8.0-ibm
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | java-1.7.1-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.8.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | java-1.7.1-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 7 | java-1.8.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 8 | java-1.8.0-ibm | Not affected | n/a |
| Red Hat Satellite 5 | java-1.8.0-ibm | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the Linux builds of IBM JDK, only version for AIX operating system were affected.
References (7)
- http://www.ibm.com/support/docview.wss?uid=ibm10960422 x_refsource_CONFIRMVendor Advisory
- https://access.redhat.com/security/cve/CVE-2019-4473 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1738558 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-14080 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/163984 vdb-entryx_refsource_XFVDB EntryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-4473
- https://www.cve.org/CVERecord?id=CVE-2019-4473
| Link | Providers | Tags |
|---|---|---|
| http://www.ibm.com/support/docview.wss?uid=ibm10960422 | x_refsource_CONFIRMVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-4473 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1738558 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-14080 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/163984 | vdb-entryx_refsource_XFVDB EntryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-4473 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-4473 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data