CVE-2021-41035

CRITICAL

Eclipse Openj9 <0.29.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.

Scores

CVSS v3 9.8
EPSS 0.0170
EPSS Percentile 74.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-440 CWE-250
Status published
Products (1)
eclipse/openj9 < 0.29.0
Published Oct 25, 2021
Tracked Since Feb 18, 2026