Type Confusion in OpenJ9 - CVE-2019-17639

 

Type Confusion in OpenJ9 - CVE-2019-17639

Published: August 11, 2020


Vulnerability identifier: #VU44142
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17639
CWE-ID: CWE-843
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error on Power platforms. A remote attacker can call the System.arraycopy method with a length longer than the length of the source or destination array and cause the current method to return prematurely with an undefined return value. As a result, a remote attacker can influence application flow and execute arbitrary code on the target system.


Affected software

OpenJ9
IBM Cloud Transformation Advisor
IBM Cloud Pak for Business Automation
IBM Cloud Application Business Insights
IBM Tivoli Monitoring
IBM CICS TX on Cloud
IBM VIOS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
IBM AIX
Red Hat Enterprise Linux for x86_64
java-1.7.1-ibm (Red Hat package)
java-1.8.0-ibm (Red Hat package)
IBM Cloud Pak System

How to mitigate CVE-2019-17639

Install updates from vendor's website.

OpenJ9 - update to 0.21.0
IBM Cloud Pak for Business Automation - update to 20.0.2 ifix 001
IBM Cloud Application Business Insights - addressed in versions 1.1.3.1, 1.1.4.2
java-1.7.1-ibm (Red Hat package) - addressed in versions 1.7.1.4.70-1jpp.1.el6_10, 1.7.1.4.70-1jpp.1.el7, 1.8.0.6.15-1.el8_2
java-1.8.0-ibm (Red Hat package) - update to 1.8.0.6.20-1jpp.1.el7
IBM Cloud Pak System - update to 2.3.3.7
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 6
IBM CICS TX on Cloud - update to 10.1.0.0 SpecialFIX 112020

External References

Related Security Bulletins