CVE Published: 17/10/2019 |
CVE Updated: 05/08/2024 |
CVE Year: 2019 Source: eclipse |
Vendor: The Eclipse Foundation |
Product: Eclipse OpenJ9 Status : PUBLISHED
CVE-2019-17631 Description
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.
CWE-ID: CWE-285 CWE Name: CWE-285: The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action. Source: The Eclipse Foundation
Common Attack Pattern Enumeration and Classification (CAPEC)