Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pm38-595m-8jp2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.

EPSS

Процентиль: 75%
0.00871
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 9.8
redhat
больше 6 лет назад

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.

CVSS3: 9.8
nvd
больше 6 лет назад

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.

CVSS3: 9.8
fstec
больше 6 лет назад

Уязвимость метода String.getBytes(int, int, byte[], int) виртуальной машины Eclipse OpenJ9, позволяющая нарушителю выполнить произвольный код

suse-cvrf
больше 6 лет назад

Security update for java-1_8_0-ibm

suse-cvrf
больше 6 лет назад

Security update for java-1_8_0-ibm

EPSS

Процентиль: 75%
0.00871
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787