Stack-based buffer overflow in OpenJ9 - CVE-2020-27221
Published: January 21, 2021 / Updated: January 21, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. A remote unauthenticated attacker can trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
IBM Cloud Transformation Advisor
IBM Sterling Control Center
IBM Integration Bus
IBM Cloud Application Business Insights
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Tivoli Monitoring
IBM CICS TX on Cloud
Planning Analytics Local
IBM Cloud Pak System
IBM VIOS
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
Red Hat Enterprise Linux Workstation
SUSE OpenStack Cloud
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
IBM AIX
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Module for Legacy Software
IBM Security Directory Suite
InfoSphere Data Replication
IBM OS Image for Red Hat Linux Systems
IBM App Connect Enterprise
java-1.7.1-ibm (Red Hat package)
java-1_8_0-ibm-plugin
java-1_8_0-ibm-alsa
java-1_8_0-ibm-devel
java-1_8_0-ibm
java-1.8.0-ibm (Red Hat package)
How to mitigate CVE-2020-27221
Planning Analytics Local - update to 2.0.9.11
IBM Cloud Pak System - update to 2.3.3.4
IBM Security Directory Suite - update to 8.0.1.16
IBM Cloud Application Business Insights - addressed in versions 1.1.5.3, 1.1.6.2
java-1.7.1-ibm (Red Hat package) - update to 1.7.1.4.80-1jpp.1.el7
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr6.25-3.50.1, 1.8.0_sr6.25-30.81.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr6.25-3.50.1, 1.8.0_sr6.25-30.81.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr6.25-3.50.1, 1.8.0_sr6.25-30.81.1
java-1_8_0-ibm - addressed in versions 1.8.0_sr6.25-3.50.1, 1.8.0_sr6.25-30.81.1
java-1.8.0-ibm (Red Hat package) - addressed in versions 1.8.0.6.25-1jpp.1.el7, 1.8.0.6.25-2.el8_3
IBM OS Image for Red Hat Linux Systems - update to 3.1.3.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.0.0
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 7
IBM CICS TX on Cloud - update to 10.1.0.0 SpecialFIX Java 042021
External References
Related Security Bulletins
- Remote code execution in Eclipse OpenJ9
- Red Hat Enterprise Linux 7 Supplementary update for java-1.8.0-ibm
- Red Hat Enterprise Linux 7 Supplementary update for java-1.7.1-ibm
- Red Hat Enterprise Linux 8 update for java-1.8.0-ibm
- IBM AIX update for Java SDK
- Remote code execution in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Planning Analytics
- Multiple vulnerabilities in IBM Sterling Control Center
- Remote code execution in IBM InfoSphere Data Replication
- Multiple vulnerabilities in IBM Security Directory Suite
- Remote code execution in IBM Integration Bus and IBM App Connect Enterpise
- Multiple vulnerabilities in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM OS Image for Red Hat Linux Systems
- IBM Cloud Application Business Insights update for Java
- IBM Tivoli Monitoring update for IBM Java
- Multiple vulnerabilities in IBM CICS TX on Cloud
- SUSE update for java-1_8_0-ibm
- SUSE update for java-1_8_0-ibm
- Multiple vulnerabilities in IBM Cloud Transformation Advisor