← Vulnerability feed

Vulnerability record · CVE-2021-28167 · published 21 April 2021

CVE-2021-28167: Eclipse openj9 vulnerability

Eclipse · Openj9

In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entries. This allows a user to call static methods or access static members without running the class initialization method, and may allow a user to observe uninitialized values.

6.5 CVSS 3.1 Medium EPSS 1.1% · top 35.0% CWE-909 · CWE-909
6.5CVSS 3.1 base score, v2 6.4
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entries. This allows a user to call static methods or access static members without running the class initialization method, and may allow a user to observe uninitialized values.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-28167 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-41035Eclipse openj9 execution with unnecessary privileges vulnerabilityIn Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.EPSS 1.8%9.8CVE-2020-27221Eclipse openj9 stack-based buffer overflow vulnerabilityIn Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are …EPSS 1.5%9.8CVE-2019-11772Eclipse openj9 out-of-bounds write vulnerabilityIn Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that …EPSS 2.1%9.8CVE-2018-12547Eclipse openj9 improper input validation vulnerabilityIn Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis…EPSS 2.7%9.8CVE-2018-12549Eclipse openj9 improper input validation vulnerabilityIn Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin…EPSS 2.3%9.8CVE-2018-12548Eclipse openj9 memory buffer overflow vulnerabilityIn OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept p…EPSS 1.1%9.1CVE-2023-2597Eclipse openj9 classic buffer overflow vulnerabilityIn Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a strin…EPSS 0.43%9.1CVE-2019-17631Eclipse openj9 improper authorization vulnerabilityFrom Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2021-28167), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.