CVE-2019-2449
published 2019-01-16CVE-2019-2449: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u192. Difficult to…
PriorityP410low3.1CVSS 3.1
AVNACHPRNUIRSUCNINAL
EPSS
2.98%
85.9th percentile
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u192. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L).
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | — | — |
| netapp | oncommand_unified_manager | >= 7.3 | — |
| netapp | oncommand_unified_manager | >= 9.4 | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | satellite | — | — |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
vendor_debian3.1LOW
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f342-vvpf-f8xr: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment)
ghsa_unreviewed·2022-05-13
CVE-2019-2449 [LOW] GHSA-f342-vvpf-f8xr: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment)
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u192. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability d
Red Hat
JDK: unspecified vulnerability fixed in 8u201 (Deployment)
vendor_redhat·2019-01-15·CVSS 3.1
CVE-2019-2449 [LOW] JDK: unspecified vulnerability fixed in 8u201 (Deployment)
JDK: unspecified vulnerability fixed in 8u201 (Deployment)
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u192. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and
Debian
CVE-2019-2449: openjdk-8 - Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployme...
vendor_debian·2019·CVSS 3.1
CVE-2019-2449 [LOW] CVE-2019-2449: openjdk-8 - Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployme...
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u192. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability d
Suricata
ET EXPLOIT Possible EXIM DoS (CVE-2019-16928)
suricata·2019-09-30·CVSS 9.8
CVE-2019-16928 [CRITICAL] ET EXPLOIT Possible EXIM DoS (CVE-2019-16928)
ET EXPLOIT Possible EXIM DoS (CVE-2019-16928)
Rule: alert smtp any any -> $SMTP_SERVERS any (msg:"ET EXPLOIT Possible EXIM DoS (CVE-2019-16928)"; flow:established,to_server; content:"EHLO "; depth:5; isdataat:5000,relative; content:!"|0a|"; within:500; reference:cve,2019-16928; reference:url,bugs.exim.org/show_bug.cgi?id=2449; reference:url,git.exim.org/exim.git/patch/478effbfd9c3cc5a627fc671d4bf94d13670d65f; classtype:attempted-admin; sid:2028636; rev:3; metadata:attack_target SMTP_Server, created_at 2019_09_30, cve CVE_2019_16928, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Critical, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_10_01;)
No public exploits indexed.
Bugzilla
CVE-2019-16928 exim: remotely triggerable buffer overflow in string_vformat()
bugzilla·2019-09-30·CVSS 9.8
CVE-2019-16928 [CRITICAL] CVE-2019-16928 exim: remotely triggerable buffer overflow in string_vformat()
CVE-2019-16928 exim: remotely triggerable buffer overflow in string_vformat()
A heap-based buffer overflow flaw was reported in the Exim's internal function string_vformat(). Additionally, it was identified that the overflow can be triggered via specially crafted SMTP protocol EHLO message, which may lead to unauthenticated remote code execution.
Upstream bug report:
https://bugs.exim.org/show_bug.cgi?id=2449
Upstream commit:
https://git.exim.org/exim.git/commitdiff/478effbfd9c3cc5a627fc671d4bf94d13670d65f
The issue was fixed upstream in version 4.92.3.
Discussion:
External References:
https://exim.org/static/doc/security/CVE-2019-16928.txt
---
Created exim tracking bugs for this issue:
Affects: epel-all [bug 1756934]
Affects: fedora-all [bug 1756933]
---
This is flaw was int
Bugzilla
CVE-2019-14540 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig
bugzilla·2019-09-26·CVSS 9.8
CVE-2019-14540 [CRITICAL] CVE-2019-14540 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig
CVE-2019-14540 jackson-databind: Serialization gadgets in com.zaxxer.hikari.HikariConfig
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
Reference:
https://github.com/FasterXML/jackson-databind/blob/master/release-notes/VERSION-2.x
https://github.com/FasterXML/jackson-databind/issues/2410
https://github.com/FasterXML/jackson-databind/issues/2449
https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E
https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1@%3Cissues.hbase.apache.org%3E
https://lists.apache.org/thread.html/a4f2c9fb36642a48912cdec6836ec00e497427717c5d377f8d7ccce6@%3Cnotification
Bugzilla
CVE-2019-2449 Oracle JDK: unspecified vulnerability fixed in 8u201 (Deployment)
bugzilla·2019-03-05·CVSS 3.1
CVE-2019-2449 [LOW] CVE-2019-2449 Oracle JDK: unspecified vulnerability fixed in 8u201 (Deployment)
CVE-2019-2449 Oracle JDK: unspecified vulnerability fixed in 8u201 (Deployment)
Oracle Java SE 8u201 fixes an unspecified vulnerability in the Deployment component (CVE-2019-2449). Upstream has CVSS scored this issue as: 3.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
External Reference:
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:0469 https://access.redhat.com/errata/RHSA-2019:0469
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Supplementary
Via RHSA-2019:0472 https://access.redhat.com/errata/RHSA-2019:0472
---
This issue has been addressed in the following products:
http://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttp://www.securityfocus.com/bid/106597https://access.redhat.com/errata/RHSA-2019:0469https://access.redhat.com/errata/RHSA-2019:0472https://access.redhat.com/errata/RHSA-2019:0640https://access.redhat.com/errata/RHSA-2019:1238https://security.netapp.com/advisory/ntap-20190118-0001/http://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttp://www.securityfocus.com/bid/106597https://access.redhat.com/errata/RHSA-2019:0469https://access.redhat.com/errata/RHSA-2019:0472https://access.redhat.com/errata/RHSA-2019:0640https://access.redhat.com/errata/RHSA-2019:1238https://security.netapp.com/advisory/ntap-20190118-0001/
2019-01-16
Published