Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37840
HistoryNov 08, 2022 - 7:11 a.m.

Out-of-bound Write

2022-11-0807:11:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
out-of-bound write
apache commons bcel
constantpool.java
constantpoolgen.java
max_cp_entries
bytecode
security vulnerability

0.019 Low

EPSS

Percentile

88.8%

Apache Commons BCEL is vulnerable to Out-of-bound Write. The vulnerability is due to ConstantPool.java and ConstantPoolGen.java improperly handing MAX_CP_ENTRIES which allows an attacker to pass data to specific APIs and control the resulting bytecode causing out-of-bound writes.