CVE-2019-2766

6 documents6 sources
Severity
3.1LOW
EPSS
1.2%
top 21.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 24

Description

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages6 packages

CVEListV5oracle_corporation/javaJava SE Embedded: 8u211, Java SE: 7u221, 8u212, 11.0.3, 12.0.1+1
NVDoracle/jdk4 versions+3
NVDoracle/jre4 versions+3
NVDhp/xp7_command_view< 8.7.0-00
NVDopensuse/leap15.0, 15.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-98rm-47wr-6469: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking)2022-05-24
CVEList
CVE-2019-2766: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking)2019-07-23

📋Vendor Advisories

2
Red Hat
OpenJDK: Insufficient permission checks for file:// URLs on Windows (Networking, 8213431)2019-07-16
Debian
CVE-2019-2766: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subc...2019

💬Community

1
Bugzilla
CVE-2019-2766 OpenJDK: Insufficient permission checks for file:// URLs on Windows (Networking, 8213431)2019-07-16
CVE-2019-2766 (LOW CVSS 3.1) | Vulnerability in the Java SE | cvebase.io