Vulnerability record · CVE-2018-12547 · published 11 February 2019
CVE-2018-12547: Eclipse openj9 improper input validation vulnerability
Eclipse · Openj9
In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly callable by non-native user code.
Description
In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly callable by non-native user code.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2019:0469 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:0472 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:0473 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:0474 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:0640 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:1238 | |
| https://bugs.eclipse.org/bugs/show_bug.cgi?id=543659 | ExploitIssue TrackingVendor Advisory |
| https://access.redhat.com/errata/RHSA-2019:0469 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:0472 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:0473 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:0474 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:0640 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:1238 | |
| https://bugs.eclipse.org/bugs/show_bug.cgi?id=543659 | ExploitIssue TrackingVendor Advisory |
Track CVE-2018-12547 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-12547), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.