CVE-2019-2989
published 2019-10-16CVE-2019-2989: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231…
PriorityP338medium6.8CVSS 3.1
AVNACHPRNUINSCCNIHAN
EPSS
3.24%
86.9th percentile
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS v3.0 Base Score 6.8 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N).
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-11 | < openjdk-11 11.0.5+10-1 (bullseye) | openjdk-11 11.0.5+10-1 (bullseye) |
| debian | openjdk-8 | < openjdk-11 11.0.5+10-1 (bullseye) | openjdk-11 11.0.5+10-1 (bullseye) |
| netapp | e-series_santricity_os_controller | 11.0.0 – 11.50.2 | — |
| oracle | graalvm | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q32p-xhjg-25f8: Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: Java)
ghsa_unreviewed·2022-05-24
CVE-2019-2989 [MEDIUM] GHSA-q32p-xhjg-25f8: Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: Java)
Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: Java). The supported version that is affected is 19.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle GraalVM Enterprise Edition accessible data. CVSS 3.0 Base Score 6.8 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N).
OSV
openjdk-8, openjdk-lts vulnerabilities
osv·2019-12-17·CVSS 3.7
CVE-2019-2894 [LOW] openjdk-8, openjdk-lts vulnerabilities
openjdk-8, openjdk-lts vulnerabilities
Jan Jancar, Petr Svenda, and Vladimir Sedlacek discovered that a side-
channel vulnerability existed in the ECDSA implementation in OpenJDK. An
Attacker could use this to expose sensitive information. (CVE-2019-2894)
It was discovered that the Socket implementation in OpenJDK did not
properly restrict the creation of subclasses with a custom Socket
implementation. An attacker could use this to specially create a Java class
that could possibly bypass Java sandbox restrictions. (CVE-2019-2945)
Rob Hamm discovered that the Kerberos implementation in OpenJDK did not
properly handle proxy credentials. An attacker could possibly use this to
impersonate another user. (CVE-2019-2949)
It was discovered that a NULL pointer dereference existed in the font
ha
OSV
CVE-2019-2989: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking)
osv·2019-10-16·CVSS 6.8
CVE-2019-2989 [MEDIUM] CVE-2019-2989: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking)
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2019-12-17·CVSS 3.7
CVE-2019-2894 [LOW] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
Jan Jancar, Petr Svenda, and Vladimir Sedlacek discovered that a side-
channel vulnerability existed in the ECDSA implementation in OpenJDK. An
Attacker could use this to expose sensitive information. (CVE-2019-2894)
It was discovered that the Socket implementation in OpenJDK did not
properly restrict the creation of subclasses with a custom Socket
implementation. An attacker could use this to specially create a Java class
that could possibly bypass Java sandbox restrictions. (CVE-2019-2945)
Rob Hamm discovered that the Kerberos implementation in OpenJDK did not
properly handle proxy credentials. An attacker could possibly use this to
impersonate another user. (CVE-2019-2949)
It was discovered that
Red Hat
OpenJDK: Incorrect handling of HTTP proxy responses in HttpURLConnection (Networking, 8225298)
vendor_redhat·2019-10-15·CVSS 6.8
CVE-2019-2989 [MEDIUM] CWE-79 OpenJDK: Incorrect handling of HTTP proxy responses in HttpURLConnection (Networking, 8225298)
OpenJDK: Incorrect handling of HTTP proxy responses in HttpURLConnection (Networking, 8225298)
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically
Debian
CVE-2019-2989: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (compon...
vendor_debian·2019·CVSS 6.8
CVE-2019-2989 [MEDIUM] CVE-2019-2989: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (compon...
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://access.redhat.com/errata/RHSA-2019:3134https://access.redhat.com/errata/RHSA-2019:3135https://access.redhat.com/errata/RHSA-2019:3136https://access.redhat.com/errata/RHSA-2019:3157https://access.redhat.com/errata/RHSA-2019:3158https://access.redhat.com/errata/RHSA-2019:4109https://access.redhat.com/errata/RHSA-2019:4110https://access.redhat.com/errata/RHSA-2019:4113https://access.redhat.com/errata/RHSA-2019:4115https://access.redhat.com/errata/RHSA-2020:0006https://access.redhat.com/errata/RHSA-2020:0046https://kc.mcafee.com/corporate/index?page=content&id=SB10315https://lists.debian.org/debian-lts-announce/2019/12/msg00005.htmlhttps://seclists.org/bugtraq/2019/Oct/27https://seclists.org/bugtraq/2019/Oct/31https://security.netapp.com/advisory/ntap-20191017-0001/https://usn.ubuntu.com/4223-1/https://www.debian.org/security/2019/dsa-4546https://www.debian.org/security/2019/dsa-4548http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://access.redhat.com/errata/RHSA-2019:3134https://access.redhat.com/errata/RHSA-2019:3135https://access.redhat.com/errata/RHSA-2019:3136https://access.redhat.com/errata/RHSA-2019:3157https://access.redhat.com/errata/RHSA-2019:3158https://access.redhat.com/errata/RHSA-2019:4109https://access.redhat.com/errata/RHSA-2019:4110https://access.redhat.com/errata/RHSA-2019:4113https://access.redhat.com/errata/RHSA-2019:4115https://access.redhat.com/errata/RHSA-2020:0006https://access.redhat.com/errata/RHSA-2020:0046https://kc.mcafee.com/corporate/index?page=content&id=SB10315https://lists.debian.org/debian-lts-announce/2019/12/msg00005.htmlhttps://seclists.org/bugtraq/2019/Oct/27https://seclists.org/bugtraq/2019/Oct/31https://security.netapp.com/advisory/ntap-20191017-0001/https://usn.ubuntu.com/4223-1/https://www.debian.org/security/2019/dsa-4546https://www.debian.org/security/2019/dsa-4548
2019-10-16
Published