PT-2019-1859 · Oracle+5 · Java Se+6

Mateusz Jurczyk

·

Published

2019-04-16

·

Updated

2022-08-12

·

CVE-2019-2697

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Java SE versions 7u211 and 8u202
Description The issue is related to insufficient access control in the 2D component of Oracle Java SE, which can be exploited by a remote attacker to gain full control over the application. This vulnerability can be difficult to exploit and allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE, resulting in a takeover of Java SE. The vulnerability applies to Java deployments that load and run untrusted code, such as sandboxed Java Web Start applications or sandboxed Java applets, and rely on the Java sandbox for security.
Recommendations For Java SE version 7u211, update to a version that contains the fix for this issue. For Java SE version 8u202, update to a version that contains the fix for this issue. As a temporary workaround, consider restricting the use of the 2D component in Java SE until a patch is available. Avoid loading and running untrusted code in Java deployments to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2019-01511
CESA-2019_1238
CVE-2019-2697
RHSA-2019:1163
RHSA-2019:1164
RHSA-2019:1165
RHSA-2019:1166
RHSA-2019:1238
RHSA-2019:1325
RHSA-2019_1163
RHSA-2019_1164
RHSA-2019_1165
RHSA-2019_1166
RHSA-2019_1238
SUSE-SU-2019:1308-1
SUSE-SU-2019:1308-2
SUSE-SU-2019:1345-1
SUSE-SU-2019:14059-1
SUSE-SU-2019:1644-1
SUSE-SU-2019_14059-1
USN-3975-1

Affected Products

Centos
Ibm Aix
Java Platform
Java Se
Red Hat
Suse
Ubuntu