Back to Database
Status published
High
CVE-2023-2597
In Eclipse Openj9 before version 0.38.0, in the implementation of...
Vulnerability Description
In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a string is not properly checked against the size of the buffer.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-2597
Credits & Attribution
No credits recorded in the NVD database.
References
More from Eclipse Foundation
View All →CVE-2025-7962
In Jakarta Mail versions prior to 2.0.2 it is possible...
Medium
6
CVE-2025-6705
A vulnerability in the Eclipse Open VSX Registry’s automated publishing...
High
7.6
CVE-2025-55102
A denial-of-service vulnerability exists in the NetX IPv6 component functionality...
High
8.7
CVE-2025-55100
Potential out-of-bounds read in _ux_host_class_audio10_sam_parse_func()
Low
2.4
CVE-2025-55099
Potential out-of-bounds read in _ux_host_class_audio_alternate_setting_locate()
Low
2.4
Affected Vendor
Eclipse Foundation
View all reports →Affected Software
Eclipse OpenJ9
Vulnerable Versions:
unspecified
Timeline
Official Publish:
May 22nd, 2023
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H