Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Jan Jancar

#51325de 53,638
4.3CVSS total
Vulnerabilidades · 1
PT-2019-3808
4.3
2019-10-15
Oracle · Java Se Embedded · CVE-2019-2894
**Name of the Vulnerable Software and Affected Versions** Java SE versions 7u231, 8u221, 11.0.4, 13 Java SE Embedded version 8u221 **Description** The issue allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE and Java SE Embedded, resulting in unauthorized read access to a subset of accessible data. This issue applies to Java deployments that load and run untrusted code and rely on the Java sandbox for security. It can also be exploited through APIs in the specified component, for example, through a web service that supplies data to the APIs. **Recommendations** For Java SE versions 7u231, 8u221, 11.0.4, 13, update to a version that includes the fix for this issue. For Java SE Embedded version 8u221, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the `Security` component until a patch is available. Avoid using APIs in the `Security` component to minimize the risk of exploitation, especially in scenarios where untrusted code is loaded and run.