Integer overflow in OpenJ9 - CVE-2024-10917

 

Integer overflow in OpenJ9 - CVE-2024-10917

Published: December 9, 2024


Vulnerability identifier: #VU101344
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-10917
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to return of an incorrect value which has wrapped around by the JNI function GetStringUTFLength. A remote attacker can pass specially crafted data to the application, trigger integer overflow and bypass security restrictions.


Affected software

OpenJ9
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Enterprise Storage
IBM i
Legacy Module
openSUSE Leap
Storage Protect for Virtual Environments: Data Protection for VMware
PowerVM NovaLink
IBM Planning Analytics Workspace
Data Product Hub
Storage Scale
Communications Server for Linux
Tivoli Monitoring for Virtual Environments Agent for Linux Kernel-based Virtual Machines
Tivoli Monitoring for Virtual Environments Base
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect Backup-Archive Client
Storage Protect for Space Management
IBM OpenPages with Watson
Storage Virtualize
Cognos Transformer
DB2 Query Management Facility
Application Modernization Accelerator
Tivoli System Automation for Multiplatforms
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
IBM Secure External Authentication Server
IBM Sterling Connect:Direct for Microsoft Windows
Security Directory Integrator
IBM Semeru Runtimes
Storage Protect Operations Center
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
Robotic Process Automation for Cloud Pak
z/Transaction Processing Facility ( z/TPF)
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Tivoli Business Service Manager
Communications Server for Linux on System z
Communications Server for Data Center Deployment
IBM Tivoli Netcool Impact
IBM Maximo Asset Management
IBM Rational Build Forge
Netcool/OMNIbus
WebSphere Service Registry and Repository
WebSphere eXtreme Scale
IBM Common Licensing
IBM Power Hardware Management Console (HMC)
IBM SPSS Modeler
IBM Content Collector for SAP Applications
IBM Cloud Transformation Advisor
IBM Tivoli System Automation Application Manager
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Sterling Secure Proxy
IBM Sterling Connect:Direct for UNIX
IBM Sterling Connect:Direct Web Services
IBM Tivoli Monitoring
Tivoli Composite Application Manager for Transactions
IBM Cloud Application Performance Management (APM)
IBM TXSeries for Multiplatforms
IBM MQ
IBM Robotic Process Automation
IBM Business Automation Workflow
Planning Analytics Local
IBM Cloud Pak System
IBM Storage Scale System
IBM Tivoli Application Dependency Discovery Manager
IBM Qradar SIEM
IBM License Metric Tool
Event Streams
Rational Business Developer (RBD)
IBM Java SDK
IBM CICS TX Advanced
IBM CICS TX Standard
IBM App Connect Enterprise
Voice Gateway
java-1_8_0-ibm-plugin
java-1_8_0-ibm-devel
java-1_8_0-ibm-alsa
java-1_8_0-ibm
java-1_8_0-ibm-devel-32bit
java-1_8_0-ibm-32bit
java-1_8_0-ibm-src
java-1_8_0-ibm-demo
IBM Copy Services Manager
IBM App Connect Professional
Juniper Secure Analytics (JSA)
IBM Security SOAR

How to mitigate CVE-2024-10917

Install updates from vendor's website.

OpenJ9 - update to 0.48.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.27.0
PowerVM NovaLink - addressed in versions 2.1.1-250324, 2.2.1.1-252403, 2.3.0.1-252403
IBM Planning Analytics Workspace - addressed in versions 2.0.103, 2.1.10
Planning Analytics Local - addressed in versions 2.0.9.21, 2.1.10
IBM Cloud Pak System - update to 2.3.6.0
Data Product Hub - update to 5.1.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 5.2
Storage Scale - addressed in versions 5.1.9.8, 5.2.2.1
IBM Storage Scale System - addressed in versions 6.1.9.6, 6.2.2.1
IBM Tivoli Business Service Manager - update to 6.2.0.6
IBM Tivoli Netcool Impact - update to 7.1.0.36
IBM Qradar SIEM - update to 7.5.0 Update Pack 11 IF01
IBM Rational Build Forge - update to 8.0.0.28
Netcool/OMNIbus - update to 8.1.0.34
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.27.0
Storage Protect Backup-Archive Client - update to 8.1.27
Storage Protect for Space Management - update to 8.1.27.0
Storage Virtualize - addressed in versions 8.4.0.16, 8.5.0.14, 8.6.0.6, 8.7.0.2, 8.7.1.0, 8.7.2.1
WebSphere eXtreme Scale - update to 8.6.1.6 PH65762
IBM License Metric Tool - update to 9.2.39
Event Streams - update to 11.5.1
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP3, 10.3.1060.0 SP1
Cognos Transformer - addressed in versions 11.2.4 FP 6, 12.0.4 FP 1
Voice Gateway - addressed in versions 1.0.8.15, 1.0.8.18
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr8.40-30.132.1, 1.8.0_sr8.40-150000.3.98.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr8.40-30.132.1, 1.8.0_sr8.40-150000.3.98.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr8.40-30.132.1, 1.8.0_sr8.40-150000.3.98.1
java-1_8_0-ibm - addressed in versions 1.8.0_sr8.40-30.132.1, 1.8.0_sr8.40-150000.3.98.1
java-1_8_0-ibm-devel-32bit - update to 1.8.0_sr8.40-150000.3.98.1
java-1_8_0-ibm-32bit - update to 1.8.0_sr8.40-150000.3.98.1
java-1_8_0-ibm-src - update to 1.8.0_sr8.40-150000.3.98.1
java-1_8_0-ibm-demo - update to 1.8.0_sr8.40-150000.3.98.1
IBM Content Collector for SAP Applications - addressed in versions 4.0.0.2.0.2, 4.0.0.3, 4.0.0.4
IBM Cloud Transformation Advisor - update to 4.0.1
Application Modernization Accelerator - update to 4.0.1
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.3.0.14, 4.1.0.4.0.11, 4.1.0.5.0.9, 4.1.0.6.0.3
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.4.0.22, 4.1.0.5.0.16, 4.1.0.6.0.11, 4.1.0.7.0.11, 4.1.1.0.0.5, 4.1.1.1.0.5
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.1
IBM Decision Optimization for Cloud Pak for Data - addressed in versions 4.8.9, 5.1.2
watsonx Assistant Cartridge - update to 5.1.3
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3
IBM Secure External Authentication Server - addressed in versions 6.0.3.1 iFix 02, 6.1.0.2 iFix 02
IBM Sterling Secure Proxy - addressed in versions 6.0.3.1 iFix 03, 6.1.0.1 iFix 03, 6.2.0.1 iFix 02
IBM Sterling Connect:Direct for UNIX - addressed in versions 6.1.0.4.121, 6.3.0.4.4, 6.4.0.1.5
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.27, 6.2.0.26
IBM Tivoli Monitoring - update to 6.3.0 FP7 Service Pack 6
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.4.15, 6.4.0.0.5
IBM Copy Services Manager - update to 6.3.14
IBM Java SDK - addressed in versions 7.1.5.24, 8.0.8.35
Security Directory Integrator - addressed in versions 7.2.0 LA0034, 10.0.0 LA0005
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.25
Juniper Secure Analytics (JSA) - update to 7.5.0 UP11 IF03
IBM App Connect Professional - update to 7.5.5.0.30
IBM Semeru Runtimes - addressed in versions 8.0.432.0, 11.0.25.0, 17.0.13.0, 21.0.5.0, 23.0.1.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.28
Storage Protect Operations Center - update to 8.1.26
CICS Transaction Gateway Desktop Edition - addressed in versions 9.1, 9.2.0.2, 9.3.0.0
CICS Transaction Gateway for Multiplatforms - addressed in versions 9.1, 9.2.0.2, 9.3.0.0
IBM TXSeries for Multiplatforms - addressed in versions 9.1.0.3, 10.1.0.0, 11.1.0.0 ifix1
IBM MQ - update to 9.4.2
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix36, 11.1.0.0 ifix28
IBM CICS TX Standard - update to 11.1.0.0 ifix29
IBM App Connect Enterprise - addressed in versions 12.0.12.9, 13.0.2.0
IBM Robotic Process Automation - addressed in versions 21.0.7.21, 23.0.20.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.21, 23.0.20.1
IBM Business Automation Workflow - addressed in versions 24.0.0-IF005, 24.0.1-IF002
IBM Security SOAR - update to 51.0.5.0

External References

Related Security Bulletins