CVE-2024-3933 is a vulnerability in Eclipse OpenJ9 versions prior to 0.44.0 and after 0.13.0, specifically when using the -Xgc:concurrentScavenge JVM option on IBM Z platforms with guarded storage. It allows out-of-bounds read and write access during System.arrayCopy operations if source and destination memory regions overlap while a Concurrent Scavenge GC cycle is active. Rated with a CVSS score of 7.3 (High), this vulnerability has a local attack vector with low attack complexity, requiring low privileges and no user interaction. Successful exploitation could lead to high confidentiality and integrity impacts, and a low availability impact. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.13.0, < 0.44.0CPE matchmatch criteria | cpe:2.3:a:eclipse:openj9:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.