PT-2019-3416 · Oracle+5 · Java Se Embedded+7
Published
2019-07-16
·
Updated
2024-06-15
·
CVE-2019-2786
CVSS v3.1
3.4
Low
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Java SE versions 8u212, 11.0.3, and 12.0.1
Java SE Embedded version 8u211
Description
The issue is related to inadequate access control in the Security component of Java SE and Java SE Embedded. Exploitation of this issue can allow an unauthenticated attacker with network access to compromise Java SE or Java SE Embedded, resulting in unauthorized read access to a subset of accessible data. The vulnerability can be exploited through APIs in the specified component, for example, through a web service that supplies data to the APIs. Successful attacks require human interaction from a person other than the attacker.
Recommendations
For Java SE versions 8u212, 11.0.3, and 12.0.1, consider restricting access to the Security component until a patch is available.
For Java SE Embedded version 8u211, consider disabling the use of APIs in the Security component as a temporary workaround.
As a general mitigation measure, avoid using Java deployments that load and run untrusted code, such as sandboxed Java Web Start applications or sandboxed Java applets, until the issue is resolved.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Ibm Aix
Java Platform
Java Se
Java Se Embedded
Red Hat
Suse
Ubuntu