CVE-2019-2602
published 2019-04-23CVE-2019-2602: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
7.44%
93.8th percentile
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-11 | < openjdk-11 11.0.3+7-1 (bullseye) | openjdk-11 11.0.3+7-1 (bullseye) |
| debian | openjdk-8 | < openjdk-11 11.0.3+7-1 (bullseye) | openjdk-11 11.0.3+7-1 (bullseye) |
| hp | xp7_command_view | < 8.6.5-00 | 8.6.5-00 |
| mcafee | epolicy_orchestrator | — | — |
| mcafee | epolicy_orchestrator | — | — |
| mcafee | epolicy_orchestrator | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2019-05-13·CVSS 7.5
CVE-2019-2602 [HIGH] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
It was discovered that the BigDecimal implementation in OpenJDK performed
excessive computation when given certain values. An attacker could use this
to cause a denial of service (excessive CPU usage). (CVE-2019-2602)
Corwin de Boor and Robert Xiao discovered that the RMI registry
implementation in OpenJDK did not properly select the correct skeleton
class in some situations. An attacker could use this to possibly escape
Java sandbox restrictions. (CVE-2019-2684)
Mateusz Jurczyk discovered a vulnerability in the 2D component of
OpenJDK. An attacker could use this to possibly escape Java sandbox
restrictions. This issue only affected OpenJDK 8 in Ubuntu 16.04
LTS. (CVE-2019-2697)
Mateusz Jurczyk disc
Red Hat
OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936)
vendor_redhat·2019-04-16·CVSS 7.5
CVE-2019-2602 [HIGH] CWE-770 OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936)
OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service
Debian
CVE-2019-2602: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subc...
vendor_debian·2019·CVSS 7.5
CVE-2019-2602 [HIGH] CVE-2019-2602: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subc...
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:
GHSA
GHSA-cq96-vcc6-mj28: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries)
ghsa_unreviewed·2022-05-24
CVE-2019-2602 [HIGH] CWE-400 GHSA-cq96-vcc6-mj28: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:
OSV
openjdk-8, openjdk-lts vulnerabilities
osv·2019-05-13·CVSS 7.5
CVE-2019-2602 [HIGH] openjdk-8, openjdk-lts vulnerabilities
openjdk-8, openjdk-lts vulnerabilities
It was discovered that the BigDecimal implementation in OpenJDK performed
excessive computation when given certain values. An attacker could use this
to cause a denial of service (excessive CPU usage). (CVE-2019-2602)
Corwin de Boor and Robert Xiao discovered that the RMI registry
implementation in OpenJDK did not properly select the correct skeleton
class in some situations. An attacker could use this to possibly escape
Java sandbox restrictions. (CVE-2019-2684)
Mateusz Jurczyk discovered a vulnerability in the 2D component of
OpenJDK. An attacker could use this to possibly escape Java sandbox
restrictions. This issue only affected OpenJDK 8 in Ubuntu 16.04
LTS. (CVE-2019-2697)
Mateusz Jurczyk discovered a vulnerability in the font layout engine
OSV
CVE-2019-2602: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries)
osv·2019-04-23·CVSS 7.5
CVE-2019-2602 [HIGH] CVE-2019-2602: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-2602 OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936)
bugzilla·2019-04-16·CVSS 7.5
CVE-2019-2602 [HIGH] CVE-2019-2602 OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936)
CVE-2019-2602 OpenJDK: Slow conversion of BigDecimal to long (Libraries, 8211936)
A flaw was found in the BigDecimal implementation in the Libraries component of OpenJDK. An untrusted numeric value parsed by a Java application could the application to use an excessive amount of CPU time.
Discussion:
Public now via Oracle CPU April 2019:
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html#AppendixJAVA
Fixed in Oracle Java 12.0.1, 11.0.3, 8u211, and 7u221.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2019:0774 https://access.redhat.com/errata/RHSA-2019:0774
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:0775 https://access.redhat.com/errata/RHSA-201
Tenable
Oracle Critical Patch Update For April Contains 297 Fixes
blogs_tenable·2019-04-17
Oracle Critical Patch Update For April Contains 297 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00058.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00013.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://access.redhat.com/errata/RHBA-2019:0959https://access.redhat.com/errata/RHSA-2019:1146https://access.redhat.com/errata/RHSA-2019:1163https://access.redhat.com/errata/RHSA-2019:1164https://access.redhat.com/errata/RHSA-2019:1165https://access.redhat.com/errata/RHSA-2019:1166https://access.redhat.com/errata/RHSA-2019:1238https://access.redhat.com/errata/RHSA-2019:1325https://access.redhat.com/errata/RHSA-2019:1518https://kc.mcafee.com/corporate/index?page=content&id=SB10285https://lists.debian.org/debian-lts-announce/2019/05/msg00011.htmlhttps://seclists.org/bugtraq/2019/May/75https://security.gentoo.org/glsa/201908-10https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03959en_ushttps://usn.ubuntu.com/3975-1/https://www.debian.org/security/2019/dsa-4453http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00058.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00013.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://access.redhat.com/errata/RHBA-2019:0959https://access.redhat.com/errata/RHSA-2019:1146https://access.redhat.com/errata/RHSA-2019:1163https://access.redhat.com/errata/RHSA-2019:1164https://access.redhat.com/errata/RHSA-2019:1165https://access.redhat.com/errata/RHSA-2019:1166https://access.redhat.com/errata/RHSA-2019:1238https://access.redhat.com/errata/RHSA-2019:1325https://access.redhat.com/errata/RHSA-2019:1518https://kc.mcafee.com/corporate/index?page=content&id=SB10285https://lists.debian.org/debian-lts-announce/2019/05/msg00011.htmlhttps://seclists.org/bugtraq/2019/May/75https://security.gentoo.org/glsa/201908-10https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03959en_ushttps://usn.ubuntu.com/3975-1/https://www.debian.org/security/2019/dsa-4453
2019-04-23
Published