CVE-2019-11772

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
17/07/2019
Last modified:
02/09/2019

Description

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:openj9:*:*:*:*:*:*:*:* 0.15.0 (excluding)