Stack-based buffer overflow in OpenJ9 - CVE-2020-27221

 

Stack-based buffer overflow in OpenJ9 - CVE-2020-27221

Published: January 21, 2021 / Updated: January 21, 2021


Vulnerability identifier: #VU49916
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27221
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. A remote unauthenticated attacker can trigger a stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

OpenJ9
IBM Cloud Transformation Advisor
IBM Sterling Control Center
IBM Integration Bus
IBM Cloud Application Business Insights
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Tivoli Monitoring
IBM CICS TX on Cloud
Planning Analytics Local
IBM Cloud Pak System
IBM VIOS
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
Red Hat Enterprise Linux Workstation
SUSE OpenStack Cloud
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
IBM AIX
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Module for Legacy Software
IBM Security Directory Suite
InfoSphere Data Replication
IBM OS Image for Red Hat Linux Systems
IBM App Connect Enterprise
java-1.7.1-ibm (Red Hat package)
java-1_8_0-ibm-plugin
java-1_8_0-ibm-alsa
java-1_8_0-ibm-devel
java-1_8_0-ibm
java-1.8.0-ibm (Red Hat package)

How to mitigate CVE-2020-27221

Install updates from vendor's website.

OpenJ9 - update to 0.24.0
Planning Analytics Local - update to 2.0.9.11
IBM Cloud Pak System - update to 2.3.3.4
IBM Security Directory Suite - update to 8.0.1.16
IBM Cloud Application Business Insights - addressed in versions 1.1.5.3, 1.1.6.2
java-1.7.1-ibm (Red Hat package) - update to 1.7.1.4.80-1jpp.1.el7
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr6.25-3.50.1, 1.8.0_sr6.25-30.81.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr6.25-3.50.1, 1.8.0_sr6.25-30.81.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr6.25-3.50.1, 1.8.0_sr6.25-30.81.1
java-1_8_0-ibm - addressed in versions 1.8.0_sr6.25-3.50.1, 1.8.0_sr6.25-30.81.1
java-1.8.0-ibm (Red Hat package) - addressed in versions 1.8.0.6.25-1jpp.1.el7, 1.8.0.6.25-2.el8_3
IBM OS Image for Red Hat Linux Systems - update to 3.1.3.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.0.0
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 7
IBM CICS TX on Cloud - update to 10.1.0.0 SpecialFIX Java 042021

External References

Related Security Bulletins