CVE-2021-41035
Summary
| CVE | CVE-2021-41035 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-25 15:15:00 UTC |
| Updated | 2021-10-28 01:21:00 UTC |
| Description | In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Throw IllegalAccessError (IAE): Lookup.findVirtual by pshipton · Pull Request #13740 · eclipse-openj9/openj9 · GitHub | CONFIRM | github.com | |
| 576395 – OpenJ9 must throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods | CONFIRM | bugs.eclipse.org | |
| CVE Request: technology.openj9 must throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods (#104) · Issues · Eclipse Foundation / EMO Team / EMO · GitLab | CONFIRM | gitlab.eclipse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 239935 Red Hat Update for java-1.8.0-ibm (RHSA-2021:5030)
- 240045 Red Hat Update for java-1.7.1-ibm (RHSA-2022:0310)
- 240054 Red Hat Update for java-1.8.0-ibm (RHSA-2022:0345)
- 330096 IBM AIX Java Multiple Vulnerabilities (java_feb2022_advisory)
- 376155 IBM Java Software Development Kit (SDK) Security Vulnerability (IBM Security Update November 2021)
- 376627 IBM Integration Bus and IBM App Connect Enterprise Multiple Vulnerabilities (6568741)
- 379452 IBM Cognos Analytics Multiple Vulnerabilities (7123154)
- 751608 SUSE Enterprise Linux Security Update for java-1_8_0-ibm (SUSE-SU-2022:0107-1)
- 751612 SUSE Enterprise Linux Security Update for java-1_8_0-ibm (SUSE-SU-2022:0108-1)
- 751618 OpenSUSE Security Update for java-1_8_0-ibm (openSUSE-SU-2022:0108-1)
- 751641 SUSE Enterprise Linux Security Update for java-1_7_1-ibm (SUSE-SU-2022:0166-1)
- 753215 SUSE Enterprise Linux Security Update for java-1_7_1-ibm (SUSE-SU-2022:14875-1)
- 91908 IBM Integration Bus and IBM App Connect Enterprise Multiple Vulnerabilities (6568741)