PT-2019-1872 · Oracle+7 · Java Se+9

Corwin De Boor

+1

·

Published

2019-04-16

·

Updated

2024-06-15

·

CVE-2019-2684

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Java SE versions 7u211, 8u202, 11.0.2, 12 Java SE Embedded version 8u201
Description The issue is related to the RMI component of Oracle Java SE and Java SE Embedded, which is associated with inadequate access control. This allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE or Java SE Embedded, resulting in unauthorized creation, deletion, or modification access to critical data or all accessible data. The vulnerability applies to Java deployments that load and run untrusted code and rely on the Java sandbox for security. It can also be exploited through APIs in the specified component.
Recommendations For Java SE versions 7u211, 8u202, 11.0.2, 12, update to a version that includes the fix for this issue. For Java SE Embedded version 8u201, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the RMI component until a patch is available. Avoid using APIs in the RMI component that may be exploited by an attacker.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2892
ALT-PU-2020-3213
ALT-PU-2021-2858
BDU:2019-01524
CESA-2019_0774
CESA-2019_0775
CESA-2019_0778
CESA-2019_0790
CESA-2019_0791
CESA-2019_1146
CESA-2019_1238
CESA-2019_1518
CVE-2019-2684
DLA-1782-1
DSA-4453-1
MGASA-2019-0155
OPENSUSE-SU-2019:1327-1
OPENSUSE-SU-2019:1438-1
OPENSUSE-SU-2019_1327-1
OPENSUSE-SU-2019_1438-1
OPENSUSE-SU-2019_1439-1
OPENSUSE-SU-2019_1500-1
OPENSUSE-SU-2024:10871-1
OPENSUSE-SU-2024:10872-1
OPENSUSE-SU-2024:10873-1
OPENSUSE-SU-2024:10876-1
RHSA-2019:0774
RHSA-2019:0775
RHSA-2019:0778
RHSA-2019:0790
RHSA-2019:0791
RHSA-2019:1146
RHSA-2019:1163
RHSA-2019:1164
RHSA-2019:1165
RHSA-2019:1166
RHSA-2019:1238
RHSA-2019:1325
RHSA-2019:1518
RHSA-2019_0774
RHSA-2019_0775
RHSA-2019_0778
RHSA-2019_0790
RHSA-2019_0791
RHSA-2019_1146
RHSA-2019_1163
RHSA-2019_1164
RHSA-2019_1165
RHSA-2019_1166
RHSA-2019_1238
RHSA-2019_1518
SUSE-SU-2019:1052-1
SUSE-SU-2019:1211-1
SUSE-SU-2019:1211-2
SUSE-SU-2019:1219-1
SUSE-SU-2019:1308-1
SUSE-SU-2019:1308-2
SUSE-SU-2019:1345-1
SUSE-SU-2019:1392-1
SUSE-SU-2019:14059-1
SUSE-SU-2019:1644-1
SUSE-SU-2019_14059-1
USN-3975-1

Affected Products

Alt Linux
Apache Cassandra
Centos
Ibm Aix
Java Platform
Java Se
Java Se Embedded
Red Hat
Suse
Ubuntu