CVE-2024-10917

LOW

Eclipse OpenJ9 0.8.0-0.47.0 - Integer Overflow in GetStringUTFLength

Title source: llm
STIX 2.1

Description

In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapped around. From 0.48 the value is correct but may be truncated to include a smaller number of characters.

Scores

CVSS v3 3.7
EPSS 0.0031
EPSS Percentile 54.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (1)
eclipse/openj9 0.8.0 - 0.48.0
Published Nov 11, 2024
Tracked Since Feb 18, 2026