Error Handling in OpenJ9 - CVE-2021-41041

 

Error Handling in OpenJ9 - CVE-2021-41041

Published: September 6, 2022


Vulnerability identifier: #VU67029
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-41041
CWE-ID: CWE-388
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to Java versions 8 and 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation. A remote attacker can invoke unverified methods using MethodHandles and bypass implemented security restrictions.


Affected software

OpenJ9
IBM Rational Directory Administrator (RDA)
IBM Rational Directory Server (RDS)
IBM Tivoli Netcool Configuration Manager
Rational Software Architect Designer (RSAD)
InfoSphere Data Architect
Tivoli System Automation for Multiplatforms
IBM Semeru Runtimes
IBM PureData System for Operational Analytics
IBM Tivoli Netcool Impact
IBM TXSeries for Multiplatforms
CICS Transaction Gateway
IBM Common Licensing
Rational Application Developer
Rational Functional Tester (RFT)
IBM ILOG CPLEX Optimization Studio (COS)
IBM Operations Analytics Predictive Insights
IBM Tivoli System Automation Application Manager
IBM Tivoli Monitoring
IBM Cloud Pak System
IBM VIOS
IBM AIX
openSUSE Leap
IBM Tivoli Application Dependency Discovery Manager
IBM Security Guardium
java-1_8_0-openj9-accessibility
java-1_8_0-openj9
java-1_8_0-openj9-javadoc
java-1_8_0-openj9-src
java-1_8_0-openj9-headless-debuginfo
java-1_8_0-openj9-headless
java-1_8_0-openj9-devel
java-1_8_0-openj9-demo-debuginfo
java-1_8_0-openj9-demo
java-1_8_0-openj9-debugsource
java-1_8_0-openj9-debuginfo
java-1_8_0-openj9-devel-debuginfo
IBM Java SDK
IBM CICS TX Advanced
IBM CICS TX Standard
IBM Hardware Management Console

How to mitigate CVE-2021-41041

Install updates from vendor's website.

OpenJ9 - update to 0.32.0
IBM Cloud Pak System - update to 2.3.3.6
IBM Tivoli Netcool Impact - update to 7.1.0.28
InfoSphere Data Architect - update to 9.2.1
IBM Operations Analytics Predictive Insights - update to 1.3.6.6
java-1_8_0-openj9-accessibility - update to 1.8.0.345-150200.3.24.1
java-1_8_0-openj9 - update to 1.8.0.345-150200.3.24.1
java-1_8_0-openj9-javadoc - update to 1.8.0.345-150200.3.24.1
java-1_8_0-openj9-src - update to 1.8.0.345-150200.3.24.1
java-1_8_0-openj9-headless-debuginfo - update to 1.8.0.345-150200.3.24.1
java-1_8_0-openj9-headless - update to 1.8.0.345-150200.3.24.1
java-1_8_0-openj9-devel - update to 1.8.0.345-150200.3.24.1
java-1_8_0-openj9-demo-debuginfo - update to 1.8.0.345-150200.3.24.1
java-1_8_0-openj9-demo - update to 1.8.0.345-150200.3.24.1
java-1_8_0-openj9-debugsource - update to 1.8.0.345-150200.3.24.1
java-1_8_0-openj9-debuginfo - update to 1.8.0.345-150200.3.24.1
java-1_8_0-openj9-devel-debuginfo - update to 1.8.0.345-150200.3.24.1
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.2.0.13, 4.1.0.3.0.9, 4.1.0.4.0.6, 4.1.0.5.0.4
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.4.0.17, 4.1.0.5.0.11, 4.1.0.6.0.6, 4.1.0.7.0.4
IBM Tivoli Monitoring - update to 6.3.0.7 Service pack 13
IBM Java SDK - update to 8.0-7.10
IBM Semeru Runtimes - addressed in versions 8.0.332.0, 11.0.15.0
IBM Hardware Management Console - addressed in versions 9.2.953.0, 10.1.1020.0
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix11, 11.1.0.0 ifix4
IBM CICS TX Standard - update to 11.1.0.0 ifix4

External References

Related Security Bulletins