From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openj9 | Eclipse | 0.15.0 (including) | 0.16.0 (including) |
Red Hat Enterprise Linux 6 Supplementary | RedHat | java-1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10 | * |
Red Hat Enterprise Linux 7 Supplementary | RedHat | java-1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el7 | * |
Red Hat Enterprise Linux 8 | RedHat | java-1.8.0-ibm-1:1.8.0.6.0-3.el8_1 | * |
Red Hat Satellite 5.8 | RedHat | java-1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10 | * |