IBM JDK 7 SR10 FP50 (7.0.10.50), 7.1 SR4 FP50 (7.1.4.50), and 8 SR5 FP40 (8.0.5.40) fix a flaw described by upstream as: Eclipse OpenJ9 could allow a local attacker to gain elevated privileges on the system, caused by the inclusion of unused RPATHS in AIX builds. An attacker could exploit this vulnerability to inject code and gain elevated privileges on the system. OpenJ9 upstream bug: https://bugs.eclipse.org/bugs/show_bug.cgi?id=548055 References: https://www-01.ibm.com/support/docview.wss?uid=ibm10960422 https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_July_2019
Upstream indicates this only affected IBM JDK builds for the IBM AIX platform and hence did not affect Linux builds.
Statement: This issue did not affect the Linux builds of IBM JDK, only version for AIX operating system were affected.