From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://bugs.eclipse.org/bugs/show_bug.cgi?id=552129 | issue tracking vendor advisory |
https://access.redhat.com/errata/RHSA-2019:4113 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2019:4115 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2020:0006 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2020:0046 | third party advisory vendor advisory |