Vulnerability Details CVE-2019-11772
In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.2%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2019-11772
-
cpe:2.3:a:eclipse:openj9:0.0
-
cpe:2.3:a:eclipse:openj9:0.10.0
-
cpe:2.3:a:eclipse:openj9:0.11.0
-
cpe:2.3:a:eclipse:openj9:0.12.0
-
cpe:2.3:a:eclipse:openj9:0.12.1
-
cpe:2.3:a:eclipse:openj9:0.13.0
-
cpe:2.3:a:eclipse:openj9:0.14.0
-
cpe:2.3:a:eclipse:openj9:0.14.1
-
cpe:2.3:a:eclipse:openj9:0.14.2
-
cpe:2.3:a:eclipse:openj9:0.14.3
-
cpe:2.3:a:eclipse:openj9:0.8
-
cpe:2.3:a:eclipse:openj9:0.8.0
-
cpe:2.3:a:eclipse:openj9:0.9.0