CVE-2021-41035
published 2021-10-25CVE-2021-41035: In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.70%
74.6th percentile
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| eclipse | openj9 | < 0.29.0 | 0.29.0 |
| the_eclipse_foundation | eclipse_omr | >= unspecified < 0.29.0 | 0.29.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cj9m-62w3-rj89: In Eclipse Openj9 before version 0
ghsa_unreviewed·2022-05-24
CVE-2021-41035 [CRITICAL] CWE-250 GHSA-cj9m-62w3-rj89: In Eclipse Openj9 before version 0
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
Red Hat
JDK: IllegalAccessError exception not thrown for MethodHandles that invoke inaccessible interface methods
vendor_redhat·2021-11-30·CVSS 9.8
CVE-2021-41035 [CRITICAL] CWE-732 JDK: IllegalAccessError exception not thrown for MethodHandles that invoke inaccessible interface methods
JDK: IllegalAccessError exception not thrown for MethodHandles that invoke inaccessible interface methods
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.eclipse.org/bugs/show_bug.cgi?id=576395https://github.com/eclipse-openj9/openj9/pull/13740https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104https://security.netapp.com/advisory/ntap-20240621-0006/https://bugs.eclipse.org/bugs/show_bug.cgi?id=576395https://github.com/eclipse-openj9/openj9/pull/13740https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104https://security.netapp.com/advisory/ntap-20240621-0006/
2021-10-25
Published