CVE-2019-2945Corporation Java vulnerability

10 documents8 sources
Severity
3.1LOWNVD
EPSS
0.3%
top 47.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthor

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:LExploitability: 1.6 | Impact: 1.4

Affected Packages9 packages

CVEListV5oracle_corporation/javaJava SE Embedded: 8u221, Java SE: 7u231, 8u221, 11.0.4, 13+1
NVDoracle/jdk4 versions+3
NVDoracle/jre4 versions+3
NVDopensuse/leap15.0, 15.1+1

Also affects: Debian Linux 10.0, 8.0, 9.0, Ubuntu Linux 16.04, 18.04, 19.04, 19.10, Enterprise Linux 8.0, 7.7, 8.1, 8.6

Patches

🔴Vulnerability Details

4
GHSA
GHSA-r4rr-2jhp-m6wm: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking)2022-05-24
OSV
openjdk-8, openjdk-lts vulnerabilities2019-12-17
CVEList
CVE-2019-2945: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking)2019-10-16
OSV
CVE-2019-2945: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking)2019-10-16

📋Vendor Advisories

3
Ubuntu
OpenJDK vulnerabilities2019-12-17
Red Hat
OpenJDK: Missing restrictions on use of custom SocketImpl (Networking, 8218573)2019-10-15
Debian
CVE-2019-2945: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (compon...2019

💬Community

2
Bugzilla
CVE-2019-2945 OpenJDK: Missing restrictions on use of custom SocketImpl (Networking, 8218573)2019-10-14
Bugzilla
CVE-2019-11072 lighttpd: signed integer overflow causing denial of service2019-04-15
CVE-2019-2945 — Oracle Corporation Java vulnerability | cvebase