PT-2024-16639 · Eclipse+2 · Eclipse Openj9+2

Published

2024-11-11

·

Updated

2025-04-25

·

CVE-2024-10917

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Eclipse OpenJ9 versions up to 0.47
Description The JNI function GetStringUTFLength may return an incorrect value which has wrapped around. From version 0.48, the value is correct but may be truncated to include a smaller number of characters.
Recommendations For Eclipse OpenJ9 versions up to 0.47, update to version 0.48 or later to resolve the issue. As a temporary workaround, consider implementing input validation to handle potential incorrect values returned by the GetStringUTFLength function until a patch is available.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-10917
OPENSUSE-SU-2025_0674-1
SUSE-SU-2025:0674-1
SUSE-SU-2025:0675-1
SUSE-SU-2025_0674-1
SUSE-SU-2025_0675-1

Affected Products

Eclipse Openj9
Ibm Aix
Suse