← Vulnerability feed

Vulnerability record · CVE-2019-11772 · published 17 July 2019

CVE-2019-11772: Eclipse openj9 out-of-bounds write vulnerability

Eclipse · Openj9

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.

9.8 CVSS 3.0 Critical EPSS 2.1% · top 19.1% CWE-787 · Out-of-bounds write
9.8CVSS 3.0 base score, v2 7.5
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-11772 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-41035Eclipse openj9 execution with unnecessary privileges vulnerabilityIn Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.EPSS 1.8%9.8CVE-2020-27221Eclipse openj9 stack-based buffer overflow vulnerabilityIn Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are …EPSS 1.5%9.8CVE-2018-12547Eclipse openj9 improper input validation vulnerabilityIn Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis…EPSS 2.7%9.8CVE-2018-12549Eclipse openj9 improper input validation vulnerabilityIn Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin…EPSS 2.3%9.8CVE-2018-12548Eclipse openj9 memory buffer overflow vulnerabilityIn OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept p…EPSS 1.1%9.1CVE-2023-2597Eclipse openj9 classic buffer overflow vulnerabilityIn Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a strin…EPSS 0.43%9.1CVE-2019-17631Eclipse openj9 improper authorization vulnerabilityFrom Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…EPSS 2.1%8.7CVE-2026-6918Eclipse openj9 out-of-bounds read vulnerabilityIn Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2019-11772), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.