IBM JDK 7 SR11 (7.0.11.0), 7.1 SR5 (7.1.5.0), and 8 SR7 (8.0.7.0) fix a flaw in OpenJ9 VM described by upstream as: In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. References: https://www.ibm.com/support/pages/java-sdk-security-vulnerabilities#IBM_Security_Update_November_2021 https://bugs.eclipse.org/bugs/show_bug.cgi?id=576395 https://github.com/eclipse-openj9/openj9/pull/13740 https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104
IBM has not published their full CVSS vector yet, only the CVSS score of 5.3. Eclipse Foundation's CVE request issue does include any CVSS score or impact rating form the OpenJ9 upstream: https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104
In reply to comment #1: > IBM has not published their full CVSS vector yet, only the CVSS score of 5.3. IBM CVSS score is now available via their security bulletin: https://www.ibm.com/support/pages/node/6522860 which notes: CVEID: CVE-2021-41035 DESCRIPTION: Eclipse Openj9 could provide weaker than expected security, caused by the failure to throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. An attacker could exploit this vulnerability to launch further attacks on the system. CVSS Base score: 5.3 CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2021:5030 https://access.redhat.com/errata/RHSA-2021:5030
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2022:0310 https://access.redhat.com/errata/RHSA-2022:0310
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:0345 https://access.redhat.com/errata/RHSA-2022:0345
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-41035