From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.
References
Link | Resource |
---|---|
https://bugs.eclipse.org/bugs/show_bug.cgi?id=552129 | Issue Tracking Vendor Advisory |
https://access.redhat.com/errata/RHSA-2019:4113 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2019:4115 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2020:0006 | Third Party Advisory |
https://access.redhat.com/errata/RHSA-2020:0046 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2019-10-17 11:15
Updated : 2020-10-16 07:20
NVD link : CVE-2019-17631
Mitre link : CVE-2019-17631
JSON object : View
CWE
CWE-269
Improper Privilege Management
Products Affected
redhat
- enterprise_linux_desktop
- enterprise_linux
- enterprise_linux_workstation
- satellite
- enterprise_linux_server
- enterprise_linux_eus
eclipse
- openj9