CVE-2021-41035: Critical severity eclipse openj9 vulnerability
Eclipse Openj9 could allow a remote attacker to gain elevated privileges on the system, caused by not throwing IllegalAccessError for MethodHandles that invoke inaccessible interface methods. By persuading a victim to execute a specially-crafted program under a security manager, an attacker could exploit this vulnerability to gain elevated privileges and execute arbitrary code on the system.
Other sources
IBM JDK 7 SR11 (7.0.11.0), 7.1 SR5 (7.1.5.0), and 8 SR7 (8.0.7.0) fix a flaw in OpenJ9 VM described by upstream as:
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
References:
https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBMSecurityUpdateNovember2021 https://bugs.eclipse.org/bugs/showbug.cgi?id=576395 https://github.com/eclipse-openj9/openj9/pull/13740 https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-41035?
CVE-2021-41035 is a vulnerability in Eclipse Openj9 that allows a remote attacker to gain elevated privileges on the system.
How severe is CVE-2021-41035?
CVE-2021-41035 has a severity score of 7.7, indicating a high severity.
Which software is affected by CVE-2021-41035?
The affected software includes Eclipse Openj9 versions before 0.29.0.
How can I fix CVE-2021-41035?
To fix CVE-2021-41035, update Eclipse Openj9 to version 0.29.0 or later.
Where can I find more information about CVE-2021-41035?
You can find more information about CVE-2021-41035 at the following references: [link1], [link2], [link3].