IBM JDK 8 SR6 FP5 (8.0.6.5) fixes a flaw described by upstream as: IBM SDK, Java Technology Edition Version could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially-crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. Note: CVE-2019-4732 is only applicable on Microsoft Windows. References: https://www.ibm.com/support/pages/node/1288060 https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_January_2020
Upstream advisory notes that this only affected IBM JDK versions for Microsoft Windows. Version for other platforms were not affected.