CVE-2021-41041
MEDIUMEclipse Openj9 <0.32.0 - Code Injection
Title source: llmDescription
In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.
Scores
CVSS v3
5.3
EPSS
0.0010
EPSS Percentile
28.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-252
CWE-843
CWE-908
Status
published
Affected Products (3)
eclipse/openj9
< 0.32.0
oracle/java_se
oracle/java_se
Timeline
Published
Apr 27, 2022
Tracked Since
Feb 18, 2026