CVE-2019-10245

In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
Affected Products (NVD)
VendorProductVersion
eclipseopenj9
𝑥
< 0.14.0
redhatsatellite
5.8
redhatenterprise_linux
8.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
java-1.7.1-ibm
RHEL 6
1:1.7.1.4.45-1jpp.1.el6_10
fixed
RHEL 7
1:1.7.1.4.45-1jpp.1.el7
fixed
java-1.7.1-ibm-demo
RHEL 6
1:1.7.1.4.45-1jpp.1.el6_10
fixed
RHEL 7
1:1.7.1.4.45-1jpp.1.el7
fixed
java-1.7.1-ibm-devel
RHEL 6
1:1.7.1.4.45-1jpp.1.el6_10
fixed
RHEL 7
1:1.7.1.4.45-1jpp.1.el7
fixed
java-1.7.1-ibm-jdbc
RHEL 6
1:1.7.1.4.45-1jpp.1.el6_10
fixed
RHEL 7
1:1.7.1.4.45-1jpp.1.el7
fixed
java-1.7.1-ibm-plugin
RHEL 6
1:1.7.1.4.45-1jpp.1.el6_10
fixed
RHEL 7
1:1.7.1.4.45-1jpp.1.el7
fixed
java-1.7.1-ibm-src
RHEL 6
1:1.7.1.4.45-1jpp.1.el6_10
fixed
RHEL 7
1:1.7.1.4.45-1jpp.1.el7
fixed
java-1.8.0-ibm
RHEL 6
1:1.8.0.5.35-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.5.35-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.5.35-3.el8_0
fixed
RHEL 8.0 E4S
1:1.8.0.5.35-3.el8_0
fixed
java-1.8.0-ibm-demo
RHEL 6
1:1.8.0.5.35-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.5.35-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.5.35-3.el8_0
fixed
RHEL 8.0 E4S
1:1.8.0.5.35-3.el8_0
fixed
java-1.8.0-ibm-devel
RHEL 6
1:1.8.0.5.35-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.5.35-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.5.35-3.el8_0
fixed
RHEL 8.0 E4S
1:1.8.0.5.35-3.el8_0
fixed
java-1.8.0-ibm-headless
RHEL 8
1:1.8.0.5.35-3.el8_0
fixed
RHEL 8.0 E4S
1:1.8.0.5.35-3.el8_0
fixed
java-1.8.0-ibm-jdbc
RHEL 6
1:1.8.0.5.35-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.5.35-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.5.35-3.el8_0
fixed
RHEL 8.0 E4S
1:1.8.0.5.35-3.el8_0
fixed
java-1.8.0-ibm-plugin
RHEL 6
1:1.8.0.5.35-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.5.35-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.5.35-3.el8_0
fixed
RHEL 8.0 E4S
1:1.8.0.5.35-3.el8_0
fixed
java-1.8.0-ibm-src
RHEL 6
1:1.8.0.5.35-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.5.35-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.5.35-3.el8_0
fixed
RHEL 8.0 E4S
1:1.8.0.5.35-3.el8_0
fixed
java-1.8.0-ibm-webstart
RHEL 8
1:1.8.0.5.35-3.el8_0
fixed
RHEL 8.0 E4S
1:1.8.0.5.35-3.el8_0
fixed