CVE-2020-27221

Description

In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.727

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.3.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.4.0Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.10Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.3Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.4Windows
Multiple Vulnerabilities are affected in IBM Planning Analytics Local 2.0Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.8Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.9Windows
Multiple Vulnerabilities are affected in IBM MQ 8.0Windows
Multiple Vulnerabilities are affected in IBM MQ 9.0Windows
Multiple Vulnerabilities are affected in IBM MQ 9.1Windows
Multiple Vulnerabilities are affected in IBM MQ 9.2Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 8.2.0.2Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 9.1.0.1Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.9Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.5.4Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.1.1.1Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0.8Windows
Vulnerabilities CVE-2020-14782,CVE-2020-27221 are affected in IBM Spectrum Protect Server 7.1.13.000Windows
Vulnerabilities CVE-2020-14782,CVE-2020-27221,CVE-2021-20491 are affected in IBM Spectrum Protect Server 8.1.11.000Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.5.3Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.1.0.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.1.1.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.1.1.2Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.8Windows
SUSE-SU-2021:0512-1(SUSE Linux Enterprise Server 12-SP5 ) java-1_7_1-ibm-1.7.1_sr4.80-38.62.1.x86_64.rpmLinux
SUSE-SU-2021:0512-1(SUSE Linux Enterprise Server 12-SP5 ) java-1_7_1-ibm-alsa-1.7.1_sr4.80-38.62.1.x86_64.rpmLinux
SUSE-SU-2021:0512-1(SUSE Linux Enterprise Server 12-SP5 ) java-1_7_1-ibm-devel-1.7.1_sr4.80-38.62.1.x86_64.rpmLinux
SUSE-SU-2021:0512-1(SUSE Linux Enterprise Server 12-SP5 ) java-1_7_1-ibm-jdbc-1.7.1_sr4.80-38.62.1.x86_64.rpmLinux
SUSE-SU-2021:0512-1(SUSE Linux Enterprise Server 12-SP5 ) java-1_7_1-ibm-plugin-1.7.1_sr4.80-38.62.1.x86_64.rpmLinux
(RHSA-2021:0717) java-1.8.0-ibm security update java-1.8.0-ibm-1.8.0.6.25-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2021:0717) java-1.8.0-ibm security update java-1.8.0-ibm-demo-1.8.0.6.25-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2021:0717) java-1.8.0-ibm security update java-1.8.0-ibm-devel-1.8.0.6.25-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2021:0717) java-1.8.0-ibm security update java-1.8.0-ibm-jdbc-1.8.0.6.25-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2021:0717) java-1.8.0-ibm security update java-1.8.0-ibm-plugin-1.8.0.6.25-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2021:0717) java-1.8.0-ibm security update java-1.8.0-ibm-src-1.8.0.6.25-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2021:0733) java-1.7.1-ibm security update java-1.7.1-ibm-1.7.1.4.80-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2021:0733) java-1.7.1-ibm security update java-1.7.1-ibm-demo-1.7.1.4.80-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2021:0733) java-1.7.1-ibm security update java-1.7.1-ibm-devel-1.7.1.4.80-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2021:0733) java-1.7.1-ibm security update java-1.7.1-ibm-jdbc-1.7.1.4.80-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2021:0733) java-1.7.1-ibm security update java-1.7.1-ibm-plugin-1.7.1.4.80-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2021:0733) java-1.7.1-ibm security update java-1.7.1-ibm-src-1.7.1.4.80-1jpp.1.el7.x86_64.rpmLinux
(RHSA-2021:0736) java-1.8.0-ibm security update java-1.8.0-ibm-1.8.0.6.25-2.el8_3.x86_64.rpmLinux
(RHSA-2021:0736) java-1.8.0-ibm security update java-1.8.0-ibm-demo-1.8.0.6.25-2.el8_3.x86_64.rpmLinux
(RHSA-2021:0736) java-1.8.0-ibm security update java-1.8.0-ibm-devel-1.8.0.6.25-2.el8_3.x86_64.rpmLinux
(RHSA-2021:0736) java-1.8.0-ibm security update java-1.8.0-ibm-headless-1.8.0.6.25-2.el8_3.x86_64.rpmLinux
(RHSA-2021:0736) java-1.8.0-ibm security update java-1.8.0-ibm-jdbc-1.8.0.6.25-2.el8_3.x86_64.rpmLinux
(RHSA-2021:0736) java-1.8.0-ibm security update java-1.8.0-ibm-plugin-1.8.0.6.25-2.el8_3.x86_64.rpmLinux
(RHSA-2021:0736) java-1.8.0-ibm security update java-1.8.0-ibm-src-1.8.0.6.25-2.el8_3.x86_64.rpmLinux
(RHSA-2021:0736) java-1.8.0-ibm security update java-1.8.0-ibm-webstart-1.8.0.6.25-2.el8_3.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234