CVE-2019-2999
published 2019-10-16CVE-2019-2999: Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13…
PriorityP425medium4.7CVSS 3.1
AVNACHPRNUIRSCCLILAN
EPSS
2.67%
84.1th percentile
Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 4.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N).
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-11 | < openjdk-11 11.0.5+10-1 (bullseye) | openjdk-11 11.0.5+10-1 (bullseye) |
| debian | openjdk-8 | < openjdk-11 11.0.5+10-1 (bullseye) | openjdk-11 11.0.5+10-1 (bullseye) |
| netapp | e-series_santricity_os_controller | 11.0.0 – 11.50.2 | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2019-12-17·CVSS 3.7
CVE-2019-2894 [LOW] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
Jan Jancar, Petr Svenda, and Vladimir Sedlacek discovered that a side-
channel vulnerability existed in the ECDSA implementation in OpenJDK. An
Attacker could use this to expose sensitive information. (CVE-2019-2894)
It was discovered that the Socket implementation in OpenJDK did not
properly restrict the creation of subclasses with a custom Socket
implementation. An attacker could use this to specially create a Java class
that could possibly bypass Java sandbox restrictions. (CVE-2019-2945)
Rob Hamm discovered that the Kerberos implementation in OpenJDK did not
properly handle proxy credentials. An attacker could possibly use this to
impersonate another user. (CVE-2019-2949)
It was discovered that
Red Hat
OpenJDK: Insufficient filtering of HTML event attributes in Javadoc (Javadoc, 8226765)
vendor_redhat·2019-10-15·CVSS 4.7
CVE-2019-2999 [MEDIUM] CWE-79 OpenJDK: Insufficient filtering of HTML event attributes in Javadoc (Javadoc, 8226765)
OpenJDK: Insufficient filtering of HTML event attributes in Javadoc (Javadoc, 8226765)
Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies
Debian
CVE-2019-2999: openjdk-11 - Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Sup...
vendor_debian·2019·CVSS 4.7
CVE-2019-2999 [MEDIUM] CVE-2019-2999: openjdk-11 - Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Sup...
Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications
GHSA
GHSA-93p8-mvm4-c85w: Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc)
ghsa_unreviewed·2022-05-24
CVE-2019-2999 [MEDIUM] GHSA-93p8-mvm4-c85w: Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc)
Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications
OSV
openjdk-8, openjdk-lts vulnerabilities
osv·2019-12-17·CVSS 3.7
CVE-2019-2894 [LOW] openjdk-8, openjdk-lts vulnerabilities
openjdk-8, openjdk-lts vulnerabilities
Jan Jancar, Petr Svenda, and Vladimir Sedlacek discovered that a side-
channel vulnerability existed in the ECDSA implementation in OpenJDK. An
Attacker could use this to expose sensitive information. (CVE-2019-2894)
It was discovered that the Socket implementation in OpenJDK did not
properly restrict the creation of subclasses with a custom Socket
implementation. An attacker could use this to specially create a Java class
that could possibly bypass Java sandbox restrictions. (CVE-2019-2945)
Rob Hamm discovered that the Kerberos implementation in OpenJDK did not
properly handle proxy credentials. An attacker could possibly use this to
impersonate another user. (CVE-2019-2949)
It was discovered that a NULL pointer dereference existed in the font
ha
OSV
CVE-2019-2999: Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc)
osv·2019-10-16·CVSS 4.7
CVE-2019-2999 [MEDIUM] CVE-2019-2999: Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc)
Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-18798 libsass: heap-based buffer overflow in Sass:weaveParents in ast_sel_weave.cpp
bugzilla·2020-06-29·CVSS 6.5
CVE-2019-18798 [MEDIUM] CVE-2019-18798 libsass: heap-based buffer overflow in Sass:weaveParents in ast_sel_weave.cpp
CVE-2019-18798 libsass: heap-based buffer overflow in Sass:weaveParents in ast_sel_weave.cpp
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
Reference:
https://github.com/sass/libsass/issues/2999
Discussion:
Created libsass tracking bugs for this issue:
Affects: epel-7 [bug 1852076]
Affects: fedora-all [bug 1852075]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-18798
Bugzilla
CVE-2019-2999 OpenJDK: Insufficient filtering of HTML event attributes in Javadoc (Javadoc, 8226765)
bugzilla·2019-10-11·CVSS 4.7
CVE-2019-2999 [MEDIUM] CVE-2019-2999 OpenJDK: Insufficient filtering of HTML event attributes in Javadoc (Javadoc, 8226765)
CVE-2019-2999 OpenJDK: Insufficient filtering of HTML event attributes in Javadoc (Javadoc, 8226765)
It was discovered that Javadoc documentation generator did not properly filter all event handler attributes of HTML tags included in documentation comments in Java source code. A malicious Java source file could use this flaw to inject JavaScript into the Javadoc-generated HTML documentation pages, possibly leading to cross-site scripting (XSS) attacks.
Discussion:
Public now via Oracle CPU October 2019:
https://www.oracle.com/security-alerts/cpuoct2019.html#AppendixJAVA
Fixed in Oracle Java SE 13.0.1, 11.0.5, 8u231, and 7u241.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:3128 https://access.redhat.com/errata/RHSA-2019:3128
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://access.redhat.com/errata/RHSA-2019:3134https://access.redhat.com/errata/RHSA-2019:3135https://access.redhat.com/errata/RHSA-2019:3136https://access.redhat.com/errata/RHSA-2019:3157https://access.redhat.com/errata/RHSA-2019:3158https://access.redhat.com/errata/RHSA-2019:4109https://access.redhat.com/errata/RHSA-2019:4110https://access.redhat.com/errata/RHSA-2019:4113https://access.redhat.com/errata/RHSA-2019:4115https://access.redhat.com/errata/RHSA-2020:0006https://access.redhat.com/errata/RHSA-2020:0046https://lists.debian.org/debian-lts-announce/2019/12/msg00005.htmlhttps://seclists.org/bugtraq/2019/Oct/27https://seclists.org/bugtraq/2019/Oct/31https://security.netapp.com/advisory/ntap-20191017-0001/https://usn.ubuntu.com/4223-1/https://www.debian.org/security/2019/dsa-4546https://www.debian.org/security/2019/dsa-4548http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://access.redhat.com/errata/RHSA-2019:3134https://access.redhat.com/errata/RHSA-2019:3135https://access.redhat.com/errata/RHSA-2019:3136https://access.redhat.com/errata/RHSA-2019:3157https://access.redhat.com/errata/RHSA-2019:3158https://access.redhat.com/errata/RHSA-2019:4109https://access.redhat.com/errata/RHSA-2019:4110https://access.redhat.com/errata/RHSA-2019:4113https://access.redhat.com/errata/RHSA-2019:4115https://access.redhat.com/errata/RHSA-2020:0006https://access.redhat.com/errata/RHSA-2020:0046https://lists.debian.org/debian-lts-announce/2019/12/msg00005.htmlhttps://seclists.org/bugtraq/2019/Oct/27https://seclists.org/bugtraq/2019/Oct/31https://security.netapp.com/advisory/ntap-20191017-0001/https://usn.ubuntu.com/4223-1/https://www.debian.org/security/2019/dsa-4546https://www.debian.org/security/2019/dsa-4548
2019-10-16
Published