Unrated severityNVD Advisory· Published Jul 17, 2019· Updated Aug 4, 2024
CVE-2019-11772
CVE-2019-11772
Description
In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
24- osv-coords22 versionspkg:rpm/suse/java-1_8_0-ibm&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP1pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208
< 1.8.0_sr5.40-30.54.1+ 21 more
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-3.24.1
- (no CPE)range: < 1.8.0_sr5.40-3.24.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- (no CPE)range: < 1.8.0_sr5.40-30.54.1
- The Eclipse Foundation/Eclipse OpenJ9v5Range: unspecified
Patches
Vulnerability mechanics
References
5- access.redhat.com/errata/RHSA-2019:2585mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2019:2590mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2019:2592mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2019:2737mitrevendor-advisoryx_refsource_REDHAT
- bugs.eclipse.org/bugs/show_bug.cgimitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.