Improper access control in OpenJ9 - CVE-2021-41035

 

Improper access control in OpenJ9 - CVE-2021-41035

Published: January 27, 2022


Vulnerability identifier: #VU60083
CSH Severity: High
CVSS v4 BT: 8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2021-41035
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. The JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. A remote attacker can send a request to a non-public method and gain unauthorized access to the application.


Affected software

OpenJ9
IBM Transparent Cloud Tiering
Rational Software Architect Designer (RSAD)
Rational Software Architect Designer for WebSphere Software
Netcool Operations Insight
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM TXSeries for Multiplatforms
Rational Application Developer
IBM Rational Software Architect
IBM CICS TX on Cloud
IBM Cloud Application Business Insights
IBM Tivoli Monitoring
IBM MQ
IBM Workload Scheduler
IBM VIOS
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
IBM AIX
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Module for Legacy Software
DB2 Recovery Expert for LUW
IBM Copy Services Manager
IBM Cognos Command Center
IBM Cognos Controller
IBM Security Guardium
Sterling Connect:Direct Browser User Interface
java-1_7_0-ibm
java-1_7_0-ibm-plugin
java-1_7_0-ibm-jdbc
java-1_7_0-ibm-devel
java-1_7_0-ibm-alsa
java-1_7_1-ibm-devel
java-1_7_1-ibm
java-1_7_1-ibm-jdbc
java-1_7_1-ibm-alsa
java-1_7_1-ibm-plugin
java-1.7.1-ibm (Red Hat package)
java-1.7.1-ibm-demo (Red Hat package)
java-1.7.1-ibm-devel (Red Hat package)
java-1.7.1-ibm-jdbc (Red Hat package)
java-1.7.1-ibm-plugin (Red Hat package)
java-1.7.1-ibm-src (Red Hat package)
java-1_8_0-ibm-plugin
java-1_8_0-ibm-alsa
java-1_8_0-ibm-devel
java-1_8_0-ibm
java-1.8.0-ibm (Red Hat package)
java-1.8.0-ibm-src (Red Hat package)
java-1.8.0-ibm-plugin (Red Hat package)
java-1.8.0-ibm-jdbc (Red Hat package)
java-1.8.0-ibm-devel (Red Hat package)
java-1.8.0-ibm-demo (Red Hat package)
IBM Cognos Analytics

How to mitigate CVE-2021-41035

Install updates from vendor's website.

OpenJ9 - update to 0.29.0
IBM Transparent Cloud Tiering - update to 1.1.8.5
Netcool Operations Insight - update to 1.6.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.5
DB2 Recovery Expert for LUW - update to 5.5.0.1 IF3
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF15
IBM Cloud Application Business Insights - addressed in versions 1.1.5.6, 1.1.6.5, 1.1.7.2
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-31
java-1_7_0-ibm - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-plugin - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-jdbc - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-devel - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-alsa - update to 1.7.0_sr11.0-65.63.1
java-1_7_1-ibm-devel - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm-jdbc - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm-alsa - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm-plugin - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1.7.1-ibm (Red Hat package) - update to 1.7.1.5.0-1jpp.1.el7
java-1.7.1-ibm-demo (Red Hat package) - update to 1.7.1.5.0-1jpp.1.el7
java-1.7.1-ibm-devel (Red Hat package) - update to 1.7.1.5.0-1jpp.1.el7
java-1.7.1-ibm-jdbc (Red Hat package) - update to 1.7.1.5.0-1jpp.1.el7
java-1.7.1-ibm-plugin (Red Hat package) - update to 1.7.1.5.0-1jpp.1.el7
java-1.7.1-ibm-src (Red Hat package) - update to 1.7.1.5.0-1jpp.1.el7
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr7.0-3.53.1, 1.8.0_sr7.0-30.84.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr7.0-3.53.1, 1.8.0_sr7.0-30.84.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr7.0-3.53.1, 1.8.0_sr7.0-30.84.1
java-1_8_0-ibm - addressed in versions 1.8.0_sr7.0-3.53.1, 1.8.0_sr7.0-30.84.1
java-1.8.0-ibm (Red Hat package) - addressed in versions 1.8.0.7.0-1.el8_5, 1.8.0.7.0-1jpp.1.el7
java-1.8.0-ibm-src (Red Hat package) - update to 1.8.0.7.0-1jpp.1.el7
java-1.8.0-ibm-plugin (Red Hat package) - update to 1.8.0.7.0-1jpp.1.el7
java-1.8.0-ibm-jdbc (Red Hat package) - update to 1.8.0.7.0-1jpp.1.el7
java-1.8.0-ibm-devel (Red Hat package) - update to 1.8.0.7.0-1jpp.1.el7
java-1.8.0-ibm-demo (Red Hat package) - update to 1.8.0.7.0-1jpp.1.el7
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 12
IBM Copy Services Manager - update to 6.3.2
IBM MQ - addressed in versions 9.0.0.13, 9.1.0.10, 9.2.0.5
IBM Workload Scheduler - addressed in versions 9.4.0.7, 9.5.0.6
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2

External References

Related Security Bulletins