CVE-2019-17195
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
Affected (18)
Products: Connect2id: Nimbus Jose+jwt · Apache: Hadoop · Oracle: Communications Cloud Native Core Security Edge Protection Proxy, Communications Pricing Design Center, Data Integrator, Enterprise Manager Base Platform, Healthcare Data Repository, Insurance Policy Administration, Jd Edwards Enterpriseone Orchestrator, Jd Edwards Enterpriseone Tools, Peoplesoft Enterprise Peopletools, Policy Automation, Primavera Gateway, Solaris Cluster, Weblogic Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 7.9 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.7.0 | |
| Version 12.0.0.3.0 | |
| Version 12.2.1.4.0 | |
| Version 13.4.0.0 | |
| Version 8.1.0 | |
| From 11.0 to 11.3.1 | |
| Up to 9.2.5.3 | |
| Up to 9.2.5.3 | |
| Version 8.58 | |
| From 12.2.0 to 12.2.22 | |
| From 18.8.0 to 18.8.11 | |
| Version 4.0 | |
| Version 12.2.1.3.0 |
References (32)
Source: cve@mitre.org
Release NotesThird Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.