In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[],...
Vulnerability Description
In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-11772
Credits & Attribution
No credits recorded in the NVD database.
References
More from The Eclipse Foundation
View All →Affected Vendor
The Eclipse Foundation
View all reports →