CVE-2019-2933Corporation Java vulnerability

6 documents6 sources
Severity
3.1LOWNVD
EPSS
0.5%
top 33.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthori

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages5 packages

CVEListV5oracle_corporation/javaJava SE Embedded: 8u221, Java SE: 7u231, 8u221, 11.0.4, 13+1
NVDoracle/jdk4 versions+3
NVDoracle/jre4 versions+3
NVDopensuse/leap15.0, 15.1+1
NVDmcafee/epolicy_orchestrator5.10.0, 5.9.0, 5.9.1+2

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6q9q-g6rv-xhjc: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries)2022-05-24
CVEList
CVE-2019-2933: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries)2019-10-16

📋Vendor Advisories

2
Red Hat
OpenJDK: FilePermission checks not preformed correctly on Windows (Libraries, 8213429)2019-10-15
Debian
CVE-2019-2933: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (compon...2019

💬Community

1
Bugzilla
CVE-2019-2933 OpenJDK: FilePermission checks not preformed correctly on Windows (Libraries, 8213429)2019-11-28
CVE-2019-2933 — Oracle Corporation Java vulnerability | cvebase