IBM JDK 7 SR10 FP70 (7.0.10.70), 7.1 SR4 FP70 (7.1.4.70), and 8 SR6 FP15 (8.0.6.15) fix a flaw described by upstream as: Eclipse OpenJ9 could allow a remote attacker to obtain sensitive information, caused by the premature return of the current method with an undefined return value. By invoking the System.arraycopy method with a length longer than the length of the source or destination array can, an attacker could exploit this vulnerability to obtain sensitive information. IBM also notes that this issue is only applicable to IBM JDK on AIX and Linux on the Power platform. OpenJ9 upstream bug: https://bugs.eclipse.org/bugs/show_bug.cgi?id=563998 References: https://www.ibm.com/support/pages/node/6256562 https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBM_Security_Update_August_2020
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2020:3386 https://access.redhat.com/errata/RHSA-2020:3386
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2020:3388 https://access.redhat.com/errata/RHSA-2020:3388
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Supplementary Via RHSA-2020:3387 https://access.redhat.com/errata/RHSA-2020:3387
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-17639
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2020:5585 https://access.redhat.com/errata/RHSA-2020:5585