CVE-2019-10245
published 2019-04-19CVE-2019-10245: In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.49%
82.9th percentile
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| eclipse | openj9 | < 0.14.0 | 0.14.0 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | satellite | — | — |
| the_eclipse_foundation | eclipse_openj9 | >= unspecified < 0.14.0 | 0.14.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: Read beyond the end of bytecode array causing JVM crash
vendor_redhat·2019-04-30·CVSS 7.5
CVE-2019-10245 [HIGH] CWE-125 JDK: Read beyond the end of bytecode array causing JVM crash
JDK: Read beyond the end of bytecode array causing JVM crash
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.
GHSA
GHSA-jq73-mhwg-56vq: In Eclipse OpenJ9 prior to the 0
ghsa_unreviewed·2022-05-24
CVE-2019-10245 [HIGH] CWE-119 GHSA-jq73-mhwg-56vq: In Eclipse OpenJ9 prior to the 0
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/108094https://access.redhat.com/errata/RHSA-2019:1163https://access.redhat.com/errata/RHSA-2019:1164https://access.redhat.com/errata/RHSA-2019:1165https://access.redhat.com/errata/RHSA-2019:1166https://access.redhat.com/errata/RHSA-2019:1238https://access.redhat.com/errata/RHSA-2019:1325https://bugs.eclipse.org/bugs/show_bug.cgi?id=545588http://www.securityfocus.com/bid/108094https://access.redhat.com/errata/RHSA-2019:1163https://access.redhat.com/errata/RHSA-2019:1164https://access.redhat.com/errata/RHSA-2019:1165https://access.redhat.com/errata/RHSA-2019:1166https://access.redhat.com/errata/RHSA-2019:1238https://access.redhat.com/errata/RHSA-2019:1325https://bugs.eclipse.org/bugs/show_bug.cgi?id=545588
2019-04-19
Published