Vulnerabilities
Vulnerable Software
Eclipse:  >> Openj9  >> 0.22.0  Security Vulnerabilities
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
CVSS Score
9.8
EPSS Score
0.018
Published
2021-10-25
In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entries. This allows a user to call static methods or access static members without running the class initialization method, and may allow a user to observe uninitialized values.
CVSS Score
6.5
EPSS Score
0.011
Published
2021-04-21
In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding.
CVSS Score
9.8
EPSS Score
0.015
Published
2021-01-21


Contact Us

Shodan ® - All rights reserved