Lucene search

K
ibmIBMD44847C0B1178268FACF4BB77CCAB024FF5F8D331FF4C797F8AA7BFE137C6E80
HistoryApr 07, 2021 - 11:11 p.m.

Security Bulletin: Vulnerability in IBM Java SDK and IBM Java Runtime affects Rational Business Developer

2021-04-0723:11:18
www.ibm.com
22
ibm java sdk
ibm java runtime
rational business developer
vulnerability
eclipse openj9
buffer overflow
remote code execution
application crash
cve-2020-27221
cvss
oracle critical patch update
security bulletin

EPSS

0.004

Percentile

74.6%

Summary

There is a vulnerability in IBM® SDK Java™ Technology Edition, Version 8 and IBM® Runtime Environment Java™ Version 8 used by Rational Business Developer. Rational Business Developer has addressed the applicable CVE. This issue was disclosed as part of the IBM Java SDK and Runtime Environment updates in the Oracle January 2021 Critical Patch Update, plus CVE-2020-27221.

Vulnerability Details

CVEID:CVE-2020-27221
**DESCRIPTION:**Eclipse OpenJ9 is vulnerable to a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding. By sending an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
CVSS Base score: 9.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/195353 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
RBD 9.5
RBD 9.6

Remediation/Fixes

Product

|

VRMF

|

APAR

|

Remediation / First Fix

|

File Name


—|—|—|—|—

Rational Business Developer

|

9.5.x

|

None

| https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7ERational&product=ibm/Rational/Rational+Business+Developer&release=9.5.1.2&platform=All&function=all| RBD_9.5_IBM_JDK8_SR6_FP25

Rational Business Developer

|

9.6.x

|

None

|

https://www.ibm.com/support/fixcentral/swg/selectFixes?parent=ibm%7ERational&product=ibm/Rational/Rational+Business+Developer&release=9.6&platform=All&function=all

| RBD_9.6_IBM_JDK8_SR6_FP25

Workarounds and Mitigations

None

EPSS

0.004

Percentile

74.6%

Related for D44847C0B1178268FACF4BB77CCAB024FF5F8D331FF4C797F8AA7BFE137C6E80