PT-2019-1858 · Oracle+5 · Java Se+6

Mateusz Jurczyk

·

Published

2019-04-16

·

Updated

2024-06-15

·

CVE-2019-2698

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Java SE versions 7u211 and 8u202
Description The issue is related to insufficient access control in the Java SE 2D component, allowing a remote attacker to gain full control over the application. This vulnerability can be exploited by an unauthenticated attacker with network access via multiple protocols to compromise Java SE, potentially resulting in a takeover of Java SE. The vulnerability applies to Java deployments that load and run untrusted code, such as sandboxed Java Web Start applications or sandboxed Java applets, and rely on the Java sandbox for security.
Recommendations For Java SE version 7u211, update to a version that contains a fix for this issue. For Java SE version 8u202, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to untrusted code in sandboxed Java Web Start applications or sandboxed Java applets until a patch is available.

Exploit

Fix

Improper Access Control

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01510
BDU:2019-02461
CESA-2019_0774
CESA-2019_0775
CESA-2019_0790
CESA-2019_0791
CESA-2019_1146
CESA-2019_1238
CVE-2019-2698
DLA-1782-1
DSA-4453-1
MGASA-2019-0155
OPENSUSE-SU-2019:1438-1
OPENSUSE-SU-2019_1438-1
OPENSUSE-SU-2019_1439-1
OPENSUSE-SU-2019_1500-1
OPENSUSE-SU-2024:10876-1
RHSA-2019:0774
RHSA-2019:0775
RHSA-2019:0790
RHSA-2019:0791
RHSA-2019:1146
RHSA-2019:1163
RHSA-2019:1164
RHSA-2019:1165
RHSA-2019:1166
RHSA-2019:1238
RHSA-2019:1325
RHSA-2019_0774
RHSA-2019_0775
RHSA-2019_0790
RHSA-2019_0791
RHSA-2019_1146
RHSA-2019_1163
RHSA-2019_1164
RHSA-2019_1165
RHSA-2019_1166
RHSA-2019_1238
SUSE-SU-2019:1211-1
SUSE-SU-2019:1211-2
SUSE-SU-2019:1219-1
SUSE-SU-2019:1308-1
SUSE-SU-2019:1308-2
SUSE-SU-2019:1345-1
SUSE-SU-2019:1392-1
SUSE-SU-2019:14059-1
SUSE-SU-2019:1644-1
SUSE-SU-2019_14059-1
USN-3975-1

Affected Products

Centos
Ibm Aix
Java Platform
Java Se
Red Hat
Suse
Ubuntu