PT-2019-1945 · Oracle+5 · Java Se Embedded+7

Published

2019-04-16

·

Updated

2024-06-15

·

CVE-2019-2602

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Java SE versions 7u211, 8u202, 11.0.2, and 12 Java SE Embedded version 8u201
Description The issue is related to insufficient access controls in the Libraries component of Oracle Java SE and Java SE Embedded. It can be exploited by a remote attacker to cause a denial of service using network protocols. Successful attacks can result in the ability to cause a hang or frequently repeatable crash of Java SE and Java SE Embedded. This can be achieved by supplying data to APIs in the specified component without using untrusted Java Web Start applications or untrusted Java applets, such as through a web service.
Recommendations For Java SE versions 7u211, 8u202, 11.0.2, and 12, update to a version that contains the fix for this issue. For Java SE Embedded version 8u201, update to a version that contains the fix for this issue. As a temporary workaround, consider restricting access to the Libraries component until a patch is available. Avoid using APIs in the specified component without proper validation and sanitization of input data.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01614
CESA-2019_0774
CESA-2019_0775
CESA-2019_0778
CESA-2019_0790
CESA-2019_0791
CESA-2019_1146
CESA-2019_1238
CESA-2019_1518
CVE-2019-2602
DLA-1782-1
DSA-4453-1
MGASA-2019-0155
OPENSUSE-SU-2019:1327-1
OPENSUSE-SU-2019:1438-1
OPENSUSE-SU-2019_1327-1
OPENSUSE-SU-2019_1438-1
OPENSUSE-SU-2019_1439-1
OPENSUSE-SU-2019_1500-1
OPENSUSE-SU-2024:10871-1
OPENSUSE-SU-2024:10872-1
OPENSUSE-SU-2024:10873-1
OPENSUSE-SU-2024:10876-1
RHSA-2019:0774
RHSA-2019:0775
RHSA-2019:0778
RHSA-2019:0790
RHSA-2019:0791
RHSA-2019:1146
RHSA-2019:1163
RHSA-2019:1164
RHSA-2019:1165
RHSA-2019:1166
RHSA-2019:1238
RHSA-2019:1325
RHSA-2019:1518
RHSA-2019_0774
RHSA-2019_0775
RHSA-2019_0778
RHSA-2019_0790
RHSA-2019_0791
RHSA-2019_1146
RHSA-2019_1163
RHSA-2019_1164
RHSA-2019_1165
RHSA-2019_1166
RHSA-2019_1238
RHSA-2019_1518
SUSE-SU-2019:1052-1
SUSE-SU-2019:1211-1
SUSE-SU-2019:1211-2
SUSE-SU-2019:1219-1
SUSE-SU-2019:1308-1
SUSE-SU-2019:1308-2
SUSE-SU-2019:1345-1
SUSE-SU-2019:1392-1
SUSE-SU-2019:14059-1
SUSE-SU-2019:1644-1
SUSE-SU-2019_1052-1
SUSE-SU-2019_14059-1
USN-3975-1

Affected Products

Centos
Ibm Aix
Java Platform
Java Se
Java Se Embedded
Red Hat
Suse
Ubuntu