QID 376155

Date Published: 2021-12-20

QID 376155: IBM Java Software Development Kit (SDK) Security Vulnerability (IBM Security Update November 2021)

Eclipse Openj9 could provide weaker than expected security, caused by the failure to throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.

Affected Versions:
IBM Java SDK Prior to 7.0.11.0
IBM Java SDK Prior to 7.1.5.0
IBM Java SDK Prior to 8.0.7.0

QID Detection Logic (Authenticated):
The QID runs "java -version" command to check if vulnerable IBM Java is installed on the system.

Successful exploitation of this vulnerability may affect the Confidentiality, Integrity and availability..

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Latest service refresh packs are available at IBM SDK, Java Technology Edition Download.
    Refer to IBM Security Update November 2021 to obtain more information.
    Vendor References

    CVEs related to QID 376155

    Software Advisories
    Advisory ID Software Component Link
    IJ35976 URL Logo www.ibm.com/support/pages/apar/IJ35976