← Back

CVE-2019-2786

nvd nist
Published: Jul 23, 2019Modified: Jun 17, 2026

JSON object

Loading...
3.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Exploitability: 1.6 / Impact: 1.4
Source: NVD

Description

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N).

Affected (23)

Products: Oracle: Jdk, Jre · Opensuse: Leap · Hp: Xp7 Command View · +2 more
Show all products
2 products
Jdk
Jre
1 product
Leap
1 product
Xp7 Command View
1 product
Ubuntu Linux
6 products
Enterprise Linux
Enterprise Linux Desktop
Enterprise Linux Eus
Enterprise Linux Server
Enterprise Linux Workstation
Satellite
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.8.0 update211
Version 1.8.0 update212
Version 11.0.3
Version 12.0.1
Oracle
Version 1.8.0 update211
Version 1.8.0 update212
Version 11.0.3
Version 12.0.1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.0
Version 15.1
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 8.7.0-00
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 16.04
Version 18.04
Version 19.04
Configuration E
9 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Redhat
Version 6.0
Version 7.0
Version 8.6
Redhat
Version 6.0
Version 7.0
Redhat
Version 6.0
Version 7.0
Version 5.8

References (20)

Source: secalert_us@oracle.com
Mailing ListThird Party Advisory
Source: secalert_us@oracle.com
Mailing ListThird Party Advisory
Source: secalert_us@oracle.com
PatchVendor Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: secalert_us@oracle.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.