Improper access control in OpenJ9 - CVE-2021-41035
Published: January 27, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. The JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. A remote attacker can send a request to a non-public method and gain unauthorized access to the application.
Affected software
IBM Transparent Cloud Tiering
Rational Software Architect Designer (RSAD)
Rational Software Architect Designer for WebSphere Software
Netcool Operations Insight
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM TXSeries for Multiplatforms
Rational Application Developer
IBM Rational Software Architect
IBM CICS TX on Cloud
IBM Cloud Application Business Insights
IBM Tivoli Monitoring
IBM MQ
IBM Workload Scheduler
IBM VIOS
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
IBM AIX
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Module for Legacy Software
DB2 Recovery Expert for LUW
IBM Copy Services Manager
IBM Cognos Command Center
IBM Cognos Controller
IBM Security Guardium
Sterling Connect:Direct Browser User Interface
java-1_7_0-ibm
java-1_7_0-ibm-plugin
java-1_7_0-ibm-jdbc
java-1_7_0-ibm-devel
java-1_7_0-ibm-alsa
java-1_7_1-ibm-devel
java-1_7_1-ibm
java-1_7_1-ibm-jdbc
java-1_7_1-ibm-alsa
java-1_7_1-ibm-plugin
java-1.7.1-ibm (Red Hat package)
java-1.7.1-ibm-demo (Red Hat package)
java-1.7.1-ibm-devel (Red Hat package)
java-1.7.1-ibm-jdbc (Red Hat package)
java-1.7.1-ibm-plugin (Red Hat package)
java-1.7.1-ibm-src (Red Hat package)
java-1_8_0-ibm-plugin
java-1_8_0-ibm-alsa
java-1_8_0-ibm-devel
java-1_8_0-ibm
java-1.8.0-ibm (Red Hat package)
java-1.8.0-ibm-src (Red Hat package)
java-1.8.0-ibm-plugin (Red Hat package)
java-1.8.0-ibm-jdbc (Red Hat package)
java-1.8.0-ibm-devel (Red Hat package)
java-1.8.0-ibm-demo (Red Hat package)
IBM Cognos Analytics
How to mitigate CVE-2021-41035
IBM Transparent Cloud Tiering - update to 1.1.8.5
Netcool Operations Insight - update to 1.6.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.5
DB2 Recovery Expert for LUW - update to 5.5.0.1 IF3
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF15
IBM Cloud Application Business Insights - addressed in versions 1.1.5.6, 1.1.6.5, 1.1.7.2
Sterling Connect:Direct Browser User Interface - update to 1.5.0.2 iFix-31
java-1_7_0-ibm - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-plugin - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-jdbc - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-devel - update to 1.7.0_sr11.0-65.63.1
java-1_7_0-ibm-alsa - update to 1.7.0_sr11.0-65.63.1
java-1_7_1-ibm-devel - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm-jdbc - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm-alsa - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1_7_1-ibm-plugin - addressed in versions 1.7.1_sr5.0-26.68.1, 1.7.1_sr5.0-38.65.1
java-1.7.1-ibm (Red Hat package) - update to 1.7.1.5.0-1jpp.1.el7
java-1.7.1-ibm-demo (Red Hat package) - update to 1.7.1.5.0-1jpp.1.el7
java-1.7.1-ibm-devel (Red Hat package) - update to 1.7.1.5.0-1jpp.1.el7
java-1.7.1-ibm-jdbc (Red Hat package) - update to 1.7.1.5.0-1jpp.1.el7
java-1.7.1-ibm-plugin (Red Hat package) - update to 1.7.1.5.0-1jpp.1.el7
java-1.7.1-ibm-src (Red Hat package) - update to 1.7.1.5.0-1jpp.1.el7
java-1_8_0-ibm-plugin - addressed in versions 1.8.0_sr7.0-3.53.1, 1.8.0_sr7.0-30.84.1
java-1_8_0-ibm-alsa - addressed in versions 1.8.0_sr7.0-3.53.1, 1.8.0_sr7.0-30.84.1
java-1_8_0-ibm-devel - addressed in versions 1.8.0_sr7.0-3.53.1, 1.8.0_sr7.0-30.84.1
java-1_8_0-ibm - addressed in versions 1.8.0_sr7.0-3.53.1, 1.8.0_sr7.0-30.84.1
java-1.8.0-ibm (Red Hat package) - addressed in versions 1.8.0.7.0-1.el8_5, 1.8.0.7.0-1jpp.1.el7
java-1.8.0-ibm-src (Red Hat package) - update to 1.8.0.7.0-1jpp.1.el7
java-1.8.0-ibm-plugin (Red Hat package) - update to 1.8.0.7.0-1jpp.1.el7
java-1.8.0-ibm-jdbc (Red Hat package) - update to 1.8.0.7.0-1jpp.1.el7
java-1.8.0-ibm-devel (Red Hat package) - update to 1.8.0.7.0-1jpp.1.el7
java-1.8.0-ibm-demo (Red Hat package) - update to 1.8.0.7.0-1jpp.1.el7
IBM Tivoli Monitoring - update to 6.3.0.7 Service Pack 12
IBM Copy Services Manager - update to 6.3.2
IBM MQ - addressed in versions 9.0.0.13, 9.1.0.10, 9.2.0.5
IBM Workload Scheduler - addressed in versions 9.4.0.7, 9.5.0.6
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
External References
Related Security Bulletins
- Improper access control in Eclipse Openj9
- Red Hat Enterprise Linux 8 update for java-1.8.0-ibm
- Multiple vulnerabilities in IBM CICS TX on Cloud (IBM Java Runtime)
- IBM AIX update for Java SDK
- IBM VIOS update for Java SDK
- IBM TXSeries for Multiplatforms update for Java
- Multiple vulnerabilities in DB2 Recovery Expert for LUW
- Multiple vulnerabilities in Sterling Connect:Direct Browser User Interface
- Multiple vulnerabilities in IBM Security Guardium
- Multiple vulnerabilities in IBM Cognos Command Center
- Multiple vulnerabilities in IBM Workload Scheduler
- Multiple vulnerabilities in Netcool Operations Insight
- IBM Cloud Application Business Insights update for Java
- IBM Tivoli Monitoring update for IBM Java
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- SUSE update for java-1_8_0-ibm
- SUSE update for java-1_8_0-ibm
- SUSE update for java-1_7_1-ibm
- SUSE update for java-1_7_1-ibm
- SUSE update for java-1_7_1-ibm
- IBM Spectrum Scale Transparent Cloud Tiering update for IBM Runtime Environment Java
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Copy Services Manager
- Multiple vulnerabilities in IBM Cognos Controller
- Multiple vulnerabilities in IBM Cognos Analytics
- Red Hat Enterprise Linux 7 Supplementary update for java-1.8.0-ibm
- Red Hat Enterprise Linux 7 Supplementary update for java-1.7.1-ibm
- Multiple vulnerabilities in IBM Rational Software Architect Designer
- Multiple vulnerabilities in IBM Rational Application Developer
- Multiple vulnerabilities in IBM Rational Software Architect Designer
- Multiple vulnerabilities in IBM MQ