First published: Tue Oct 15 2019(Updated: )
A flaw was found in Connect2id Nimbus JOSE+JWT prior to version 7.9. While processing JSON web tokens (JWT), nimbus-jose-jwt can throw various uncaught exceptions resulting in an application crash, information disclosure, or authentication bypass. The highest threat from this vulnerability is to data confidentiality and system availability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/apache-commons-beanutils | <0:1.8.3-15.el7_7 | 0:1.8.3-15.el7_7 |
redhat/ovirt-engine-extension-aaa-misc | <0:1.0.4-1.el7e | 0:1.0.4-1.el7e |
redhat/ovirt-fast-forward-upgrade | <0:1.0.0-17.el7e | 0:1.0.0-17.el7e |
redhat/rhvm-dependencies | <0:4.3.2-1.el7e | 0:4.3.2-1.el7e |
redhat/nimbus-jose-jwt | <7.9 | 7.9 |
Connect2id Nimbus Jose\+jwt | <7.9 | |
Apache Hadoop | =3.2.1 | |
Oracle Communications Cloud Native Core Security Edge Protection Proxy | =1.7.0 | |
Oracle Communications Pricing Design Center | =12.0.0.3.0 | |
Oracle Data Integrator | =12.2.1.4.0 | |
Oracle Enterprise Manager Base Platform | =13.4.0.0 | |
Oracle Healthcare Data Repository | =8.1.0 | |
Oracle Insurance Policy Administration | >=11.0<=11.3.1 | |
Oracle Jd Edwards Enterpriseone Orchestrator | <=9.2.5.3 | |
Oracle Jd Edwards Enterpriseone Tools | <=9.2.5.3 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.58 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.59 | |
Oracle Policy Automation | >=12.2.0<=12.2.22 | |
Oracle Primavera Gateway | >=18.8.0<=18.8.11 | |
Oracle Primavera Gateway | =19.12.0 | |
Oracle Solaris Cluster | =4.0 | |
Oracle WebLogic Server | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.2.1.4.0 | |
<=7.0.1 | ||
<=7.0.2 | ||
<=7.0 | ||
<=All | ||
<=7.0.2 | ||
<=7.0 | ||
<=7.0.1 | ||
<=6.0.6.1 | ||
<=6.0.6 | ||
<=7.0.2 | ||
<=7.0 | ||
<=7.0.1 | ||
<=7.0.2 | ||
<=7.0.1 | ||
<=6.0.6.1 | ||
<=7.0 | ||
<=6.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17195 is a vulnerability found in Connect2id Nimbus JOSE+JWT prior to version 7.9.
The severity of CVE-2019-17195 is critical with a CVSS score of 9.8.
CVE-2019-17195 can result in an application crash, information disclosure, or authentication bypass.
To fix CVE-2019-17195, update Connect2id Nimbus JOSE+JWT to version 7.9.
You can find more information about CVE-2019-17195 at the following references: [link1], [link2], [link3].