CVE-2019-2816

high
Published 2019-07-22 ยท Modified 2019-09-02
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.0

Description

RHSA-2019:2590: java-1.8.0-ibm security update (Important)

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description OpenJDK: Missing URL format validation (Networking, 8221518) CVSS v3: 4.8 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 6java-1.8.0-openjdk-1:1.8.0.222.b10-0.el6_10RHSA-2019:18112019-07-22T00:00:00Z Red Hat Enterprise Linux 6java-1.7.0-openjdk-1:1.7.0.231-2.6.19.1.el6_10RHSA-2019:18402019-07-23T00:00:00Zโ€ฆ

Description

OpenJDK: Missing URL format validation (Networking, 8221518)

CVSS v3: 4.8 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 6java-1.8.0-openjdk-1:1.8.0.222.b10-0.el6_10RHSA-2019:18112019-07-22T00:00:00Z
Red Hat Enterprise Linux 6java-1.7.0-openjdk-1:1.7.0.231-2.6.19.1.el6_10RHSA-2019:18402019-07-23T00:00:00Z
Red Hat Enterprise Linux 6 Supplementaryjava-1.7.1-ibm-1:1.7.1.4.50-1jpp.1.el6_10RHSA-2019:24942019-08-15T00:00:00Z
Red Hat Enterprise Linux 6 Supplementaryjava-1.8.0-ibm-1:1.8.0.5.40-1jpp.1.el6_10RHSA-2019:25922019-09-03T00:00:00Z
Red Hat Enterprise Linux 7java-11-openjdk-1:11.0.4.11-0.el7_6RHSA-2019:18102019-07-22T00:00:00Z
Red Hat Enterprise Linux 7java-1.8.0-openjdk-1:1.8.0.222.b10-0.el7_6RHSA-2019:18152019-07-22T00:00:00Z
Red Hat Enterprise Linux 7java-1.7.0-openjdk-1:1.7.0.231-2.6.19.1.el7_6RHSA-2019:18392019-07-23T00:00:00Z
Red Hat Enterprise Linux 7 Supplementaryjava-1.7.1-ibm-1:1.7.1.4.50-1jpp.1.el7RHSA-2019:24952019-08-15T00:00:00Z
Red Hat Enterprise Linux 7 Supplementaryjava-1.8.0-ibm-1:1.8.0.5.40-1jpp.1.el7RHSA-2019:25852019-09-02T00:00:00Z
Red Hat Enterprise Linux 8java-1.8.0-openjdk-1:1.8.0.222.b10-0.el8_0RHSA-2019:18162019-07-22T00:00:00Z
Red Hat Enterprise Linux 8java-11-openjdk-1:11.0.4.11-0.el8_0RHSA-2019:18172019-07-22T00:00:00Z
Red Hat Enterprise Linux 8java-1.8.0-ibm-1:1.8.0.5.40-3.el8_0RHSA-2019:25902019-09-02T00:00:00Z
Red Hat Satellite 5.8java-1.8.0-ibm-1:1.8.0.5.40-1jpp.1.el6_10RHSA-2019:27372019-09-11T00:00:00Z

Apply commands

bash fix
Apply RHSA-2019:1811 for Red Hat Enterprise Linux 6
yum update -y java
# or:
dnf upgrade -y java

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbullseyefixed11.0.4+11-1
debian debiansidfixed11.0.4+11-1
redhat rhel8fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.