In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Link | Tags |
---|---|
https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104 | vendor advisory |
https://github.com/eclipse-openj9/openj9/pull/13740 | third party advisory patch |
https://bugs.eclipse.org/bugs/show_bug.cgi?id=576395 | vendor advisory |
https://security.netapp.com/advisory/ntap-20240621-0006/ |