CVE-2019-2999Cross-site Scripting in Corporation Java

Severity
4.7MEDIUMNVD
EPSS
1.3%
top 20.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vuln

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.7

Affected Packages9 packages

CVEListV5oracle_corporation/javaJava SE: 7u231, 8u221, 11.0.4, 13
NVDoracle/jdk4 versions+3
NVDoracle/jre4 versions+3
NVDopensuse/leap15.0, 15.1+1

Also affects: Debian Linux 10.0, 8.0, 9.0, Ubuntu Linux 16.04, 18.04, 19.04, 19.10, Enterprise Linux 8.0, 7.7, 8.1, 8.6

Patches

🔴Vulnerability Details

3
GHSA
GHSA-93p8-mvm4-c85w: Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc)2022-05-24
CVEList
CVE-2019-2999: Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc)2019-10-16
OSV
CVE-2019-2999: Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc)2019-10-16

📋Vendor Advisories

3
Ubuntu
OpenJDK vulnerabilities2019-12-17
Red Hat
OpenJDK: Insufficient filtering of HTML event attributes in Javadoc (Javadoc, 8226765)2019-10-15
Debian
CVE-2019-2999: openjdk-11 - Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Sup...2019

💬Community

2
Bugzilla
CVE-2019-18798 libsass: heap-based buffer overflow in Sass:weaveParents in ast_sel_weave.cpp2020-06-29
Bugzilla
CVE-2019-2999 OpenJDK: Insufficient filtering of HTML event attributes in Javadoc (Javadoc, 8226765)2019-10-11
CVE-2019-2999 — Cross-site Scripting | cvebase