CVE-2018-12539
published 2018-08-14CVE-2018-12539: In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same…
PriorityP340high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.49%
39.1th percentile
In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the ability to execute untrusted native code. Attach API is enabled by default on Windows, Linux and AIX JVMs and can be disabled using the command line option -Dcom.ibm.tools.attach.enable=no.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| eclipse | openj9 | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| the_eclipse_foundation | eclipse_openj9 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: privilege escalation via insufficiently restricted access to Attach API
vendor_redhat·2018-05-11·CVSS 7.8
CVE-2018-12539 [HIGH] CWE-287 JDK: privilege escalation via insufficiently restricted access to Attach API
JDK: privilege escalation via insufficiently restricted access to Attach API
In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the ability to execute untrusted native code. Attach API is enabled by default on Windows, Linux and AIX JVMs and can be disabled using the command line option -Dcom.ibm.tools.attach.enable=no.
GHSA
GHSA-8xmg-5xjr-x475: In Eclipse OpenJ9 version 0
ghsa_unreviewed·2022-05-13
CVE-2018-12539 [HIGH] CWE-502 GHSA-8xmg-5xjr-x475: In Eclipse OpenJ9 version 0
In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the ability to execute untrusted native code. Attach API is enabled by default on Windows, Linux and AIX JVMs and can be disabled using the command line option -Dcom.ibm.tools.attach.enable=no.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/105126http://www.securitytracker.com/id/1041765https://access.redhat.com/errata/RHSA-2018:2568https://access.redhat.com/errata/RHSA-2018:2569https://access.redhat.com/errata/RHSA-2018:2575https://access.redhat.com/errata/RHSA-2018:2576https://access.redhat.com/errata/RHSA-2018:2712https://access.redhat.com/errata/RHSA-2018:2713https://bugs.eclipse.org/bugs/show_bug.cgi?id=534589https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttp://www.securityfocus.com/bid/105126http://www.securitytracker.com/id/1041765https://access.redhat.com/errata/RHSA-2018:2568https://access.redhat.com/errata/RHSA-2018:2569https://access.redhat.com/errata/RHSA-2018:2575https://access.redhat.com/errata/RHSA-2018:2576https://access.redhat.com/errata/RHSA-2018:2712https://access.redhat.com/errata/RHSA-2018:2713https://bugs.eclipse.org/bugs/show_bug.cgi?id=534589https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
2018-08-14
Published