Описание
In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlining to access or modify memory via an incompatible type.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingVendor Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.35.0 (исключая)
cpe:2.3:a:eclipse:openj9:*:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.0038
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-20
CWE-843
EPSS
Процентиль: 59%
0.0038
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-20
CWE-843