CVE-2019-2821
OpenJDK: Incorrect handling of certificate status messages during TLS handshake (JSSE, 8222678)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 11.0.3 and 12.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).
Vulnerabilidad en el componente Java SE de Oracle Java SE (subcomponente: JSSE). Las versiones compatibles que se ven afectadas son Java SE: 11.0.3 y 12.0.1. Una vulnerabilidad difícil de explotar permite que un atacante no autenticado con acceso a la red mediante TLS comprometa a Java SE. Los ataques con éxito requieren la interacción humana con otra persona distinta al atacante. Los ataques con éxito a esta vulnerabilidad pueden resultar en un acceso no autorizado a datos críticos o un acceso completo a todos los datos accesibles de Oracle Java SE. Nota: esta vulnerabilidad se aplica a las implementaciones de Java, generalmente en clientes que ejecutan aplicaciones Java Web Start en sandboxes o en applets de Java en sandboxes (en Java SE 8), que cargan y ejecutan código no seguro (por ejemplo, código que proviene de Internet) y se basan en Java Sandbox para seguridad. Esta vulnerabilidad no se aplica a las implementaciones de Java, normalmente en servidores, que cargan y ejecutan solo código de confianza (por ejemplo, código instalado por un administrador). CVSS 3.0 Base Score 5.3 (Impactos de Confidencialidad). Vector CVSS: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2018-12-14 CVE Reserved
- 2019-07-21 CVE Published
- 2024-07-16 EPSS Updated
- 2024-10-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-358: Improperly Implemented Security Check for Standard
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html | 2020-08-24 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.html | 2020-08-24 | |
https://usn.ubuntu.com/4083-1 | 2020-08-24 | |
https://access.redhat.com/security/cve/CVE-2019-2821 | 2019-07-22 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1730251 | 2019-07-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Jdk Search vendor "Oracle" for product "Jdk" | 11.0.3 Search vendor "Oracle" for product "Jdk" and version "11.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jdk Search vendor "Oracle" for product "Jdk" | 12.0.1 Search vendor "Oracle" for product "Jdk" and version "12.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 11.0.3 Search vendor "Oracle" for product "Jre" and version "11.0.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 12.0.1 Search vendor "Oracle" for product "Jre" and version "12.0.1" | - |
Affected
|