← Vulnerability feed

Vulnerability record · CVE-2019-17639 · published 15 July 2020

CVE-2019-17639: Eclipse openj9 type confusion vulnerability

Eclipse · Openj9

In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially crafted code patterns, cause the current method to return prematurely with an undefined return value. This allows whatever value happens to be in the return register at that time to be used as if it matches the method's declared return type.

5.3 CVSS 3.1 Medium EPSS 1.5% · top 26.7% CWE-843 · Type confusion
5.3CVSS 3.1 base score, v2 5.0
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially crafted code patterns, cause the current method to return prematurely with an undefined return value. This allows whatever value happens to be in the return register at that time to be used as if it matches the method's declared return type.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-17639 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-41035Eclipse openj9 execution with unnecessary privileges vulnerabilityIn Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.EPSS 1.8%9.8CVE-2020-27221Eclipse openj9 stack-based buffer overflow vulnerabilityIn Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are …EPSS 1.5%9.8CVE-2019-11772Eclipse openj9 out-of-bounds write vulnerabilityIn Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that …EPSS 2.1%9.8CVE-2018-12547Eclipse openj9 improper input validation vulnerabilityIn Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis…EPSS 2.7%9.8CVE-2018-12549Eclipse openj9 improper input validation vulnerabilityIn Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin…EPSS 2.3%9.8CVE-2018-12548Eclipse openj9 memory buffer overflow vulnerabilityIn OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept p…EPSS 1.1%9.1CVE-2023-2597Eclipse openj9 classic buffer overflow vulnerabilityIn Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a strin…EPSS 0.43%9.1CVE-2019-17631Eclipse openj9 improper authorization vulnerabilityFrom Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2019-17639), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.