PT-2022-11360 · Oracle+4 · Java+4

Peter Shipton

·

Published

2022-04-27

·

Updated

2025-02-18

·

CVE-2021-41041

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Eclipse Openj9 versions prior to 0.32.0
Description The issue arises when Java 8 and 11 fail to throw an exception captured during bytecode verification triggered by a MethodHandle invocation. This allows unverified methods to be invoked using MethodHandles.
Recommendations For Eclipse Openj9 versions prior to 0.32.0, update to version 0.32.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of MethodHandles to minimize the risk of exploitation.

Fix

Type Confusion

Unchecked Return Value

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2022_5837
CVE-2021-41041
OPENSUSE-SU-2022_3092-1
OPENSUSE-SU-2024:12185-1
OPENSUSE-SU-2024:12186-1
OPENSUSE-SU-2025:0066-1
RHSA-2022:4959
RHSA-2022:5837
RHSA-2022_4959
RHSA-2022_5837
SUSE-SU-2022:3092-1

Affected Products

Centos
Eclipse Openj9
Java
Red Hat
Suse