CVE-2019-17631

From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
eclipseopenj9
0.15.0 ≤
𝑥
≤ 0.16.0
redhatsatellite
5.8
redhatenterprise_linux
8.0
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_eus
8.1
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
java-1.8.0-ibm
RHEL 6
1:1.8.0.6.0-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.6.0-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 E4S
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 EUS
1:1.8.0.6.0-3.el8_1
fixed
java-1.8.0-ibm-demo
RHEL 6
1:1.8.0.6.0-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.6.0-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 E4S
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 EUS
1:1.8.0.6.0-3.el8_1
fixed
java-1.8.0-ibm-devel
RHEL 6
1:1.8.0.6.0-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.6.0-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 E4S
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 EUS
1:1.8.0.6.0-3.el8_1
fixed
java-1.8.0-ibm-headless
RHEL 8
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 E4S
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 EUS
1:1.8.0.6.0-3.el8_1
fixed
java-1.8.0-ibm-jdbc
RHEL 6
1:1.8.0.6.0-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.6.0-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 E4S
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 EUS
1:1.8.0.6.0-3.el8_1
fixed
java-1.8.0-ibm-plugin
RHEL 6
1:1.8.0.6.0-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.6.0-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 E4S
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 EUS
1:1.8.0.6.0-3.el8_1
fixed
java-1.8.0-ibm-src
RHEL 6
1:1.8.0.6.0-1jpp.1.el6_10
fixed
RHEL 7
1:1.8.0.6.0-1jpp.1.el7
fixed
RHEL 8
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 E4S
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 EUS
1:1.8.0.6.0-3.el8_1
fixed
java-1.8.0-ibm-webstart
RHEL 8
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 E4S
1:1.8.0.6.0-3.el8_1
fixed
RHEL 8.1 EUS
1:1.8.0.6.0-3.el8_1
fixed