PT-2019-3439 · Oracle+4 · Java Se+5

Nati Nimni

·

Published

2019-07-16

·

Updated

2024-06-15

·

CVE-2019-2842

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Java SE version 8u212
Description The issue is related to the Java SE component, specifically the JCE subcomponent, and is associated with inadequate access control. It allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE, resulting in a partial denial of service. This issue affects Java deployments that load and run untrusted code, relying on the Java sandbox for security. It can be exploited through APIs in the specified component, for example, via a web service supplying data to the APIs.
Recommendations For Java SE version 8u212, consider disabling the use of the JCE component until a patch is available, or restrict access to APIs that could be used to exploit this issue. As a temporary workaround, avoid using web services that supply data to the APIs in the affected component. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03610
CESA-2019_1811
CESA-2019_1815
CESA-2019_1816
CESA-2019_1839
CESA-2019_1840
CVE-2019-2842
DSA-4485-1
MGASA-2019-0241
OPENSUSE-SU-2019:1912-1
OPENSUSE-SU-2019_1912-1
OPENSUSE-SU-2024:10876-1
RHSA-2019:1811
RHSA-2019:1815
RHSA-2019:1816
RHSA-2019:1839
RHSA-2019:1840
RHSA-2019_1811
RHSA-2019_1815
RHSA-2019_1816
RHSA-2019_1839
RHSA-2019_1840
SUSE-SU-2019:2021-1
SUSE-SU-2019:2028-1
SUSE-SU-2019:2036-1
SUSE-SU-2019:2036-2
USN-4080-1

Affected Products

Centos
Java Platform
Java Se
Red Hat
Suse
Ubuntu