← Back

CVE-2019-2426

nvd nist
Published: Jan 16, 2019Modified: Jun 17, 2026

JSON object

Loading...
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD

Description

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).

Affected (16)

Show all products
2 products
Jdk
Jre
3 products
Oncommand Unified Manager
Oncommand Workflow Automation
Snapmanager
1 product
Leap
1 product
Xp7 Command View
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.7.0 update201
Version 1.8.0 update191
Version 1.8.0 update192
Version 11.0.1
Oracle
Version 1.7.0 update201
Version 1.8.0 update191
Version 1.8.0 update192
Version 11.0.1
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Netapp
All versions
From 9.4
From 7.3
All versions
Netapp
All versions
All versions
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 42.3
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 8.6.4-00

References (14)

Source: secalert_us@oracle.com
Mailing ListThird Party Advisory
Source: secalert_us@oracle.com
Mailing ListThird Party Advisory
Source: secalert_us@oracle.com
PatchVendor Advisory
Source: secalert_us@oracle.com
Third Party AdvisoryVDB Entry
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.