CVE-2019-17631: Critical severity ibm engineering requirements quality assistant vulnerability
Eclipse OpenJ9 could allow a local attacker to gain elevated privileges on the system, caused by the failure to performs an authorization check when an actor attempts to access a resource or perform an action. An attacker could exploit this vulnerability to gain access to diagnostic operations such as causing a GC or creating a diagnostic file.
Other sources
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-17631?
CVE-2019-17631 is a vulnerability in Eclipse OpenJ9 that could allow a local attacker to gain elevated privileges on the system.
How can an attacker exploit CVE-2019-17631?
An attacker could exploit CVE-2019-17631 to gain access to diagnostic operations and perform unauthorized actions.
What is the severity of CVE-2019-17631?
The severity of CVE-2019-17631 is high with a severity score of 8.4.
Which software versions are affected by CVE-2019-17631?
Versions 0.15 to 0.16 of Eclipse OpenJ9 are affected by CVE-2019-17631.
How do I fix CVE-2019-17631?
To fix CVE-2019-17631, update to version 1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10 or later for Red Hat Java.