Описание
AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users.
Отчет
This issue did not affect the Linux builds of IBM JDK, only version for AIX operating system were affected.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | java-1.7.1-ibm | Not affected | ||
| Red Hat Enterprise Linux 6 | java-1.8.0-ibm | Not affected | ||
| Red Hat Enterprise Linux 7 | java-1.7.1-ibm | Not affected | ||
| Red Hat Enterprise Linux 7 | java-1.8.0-ibm | Not affected | ||
| Red Hat Enterprise Linux 8 | java-1.8.0-ibm | Not affected | ||
| Red Hat Satellite 5 | java-1.8.0-ibm | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-426
https://bugzilla.redhat.com/show_bug.cgi?id=1738559JDK: Insecure RPATH in OpenJ9 on AIX
EPSS
Процентиль: 13%
0.00043
Низкий
7.8 High
CVSS3
Связанные уязвимости
CVSS3: 7.8
nvd
больше 6 лет назад
AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users.
CVSS3: 7.8
github
больше 3 лет назад
AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users.
EPSS
Процентиль: 13%
0.00043
Низкий
7.8 High
CVSS3