Lucene search

K
ibmIBM3ABE6FDE601C97AD27F82734302A5886A687962688B6437DCA763D5AAF9022D2
HistoryJan 30, 2023 - 5:54 p.m.

Security Bulletin: IBM Workload Scheduler potentially affected by vulnerability in Eclipse Openj9 (CVE-2021-41041)

2023-01-3017:54:11
www.ibm.com
16
ibm workload scheduler
eclipse openj9 vulnerability
cve-2021-41041
remote attacker
security restrictions
methodhandles
cvss base score 5.3
apar ij45099
fixcentral

EPSS

0.001

Percentile

33.3%

Summary

Eclipse Openj9 is vulnerable to attacks bypassing security restrictions that can potentially affect IBM Workload Scheduler 9.5 and IBM Workload Scheduler 10.1

Vulnerability Details

CVEID:CVE-2021-41041
**DESCRIPTION:**Eclipse Openj9 could allow a remote attacker to bypass security restrictions, caused by failing to throw the exception captured during bytecode verification when verification. By sending a specially-crafted request, an attacker could exploit this vulnerability to make unverified methods to be invoked using MethodHandles.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/225398 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Workload Scheduler 9.5
IBM Workload Scheduler 10.1

Remediation/Fixes

APAR IJ45099 has been opened to address Eclipse Openj9 vulnerability affecting IBM Workload Scheduler.
APAR IJ45099 is included in IBM Workload Scheduler 9.5.0.6 Security Update and in IBM Workload Scheduler 10.1.0.1, both available on FixCentral.

Workarounds and Mitigations

None

EPSS

0.001

Percentile

33.3%

Related for 3ABE6FDE601C97AD27F82734302A5886A687962688B6437DCA763D5AAF9022D2