First published: Tue Apr 16 2019(Updated: )
A flaw was found in the BigDecimal implementation in the Libraries component of OpenJDK. An untrusted numeric value parsed by a Java application could the application to use an excessive amount of CPU time.
Credit: secalert_us@oracle.com secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.25+9-1~deb11u1 11.0.25+9-1 | |
debian/openjdk-8 | 8u432-b06-2 | |
Oracle JDK 6 | =1.7.0-update211 | |
Oracle JDK 6 | =1.8.0-update201 | |
Oracle JDK 6 | =1.8.0-update202 | |
Oracle JDK 6 | =11.0.2 | |
Oracle JDK 6 | =12 | |
Oracle JRE | =1.7.0-update211 | |
Oracle JRE | =1.8.0-update201 | |
Oracle JRE | =1.8.0-update202 | |
Oracle JRE | =11.0.2 | |
Oracle JRE | =12 | |
redhat openshift container platform | =3.11 | |
redhat satellite | =5.8 | |
Red Hat Enterprise Linux | =8.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux eus | =8.1 | |
redhat enterprise Linux eus | =8.2 | |
redhat enterprise Linux eus | =8.4 | |
redhat enterprise Linux eus | =8.6 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux server aus | =8.2 | |
redhat enterprise Linux server aus | =8.4 | |
redhat enterprise Linux server aus | =8.6 | |
redhat enterprise Linux server tus | =8.2 | |
redhat enterprise Linux server tus | =8.4 | |
redhat enterprise Linux server tus | =8.6 | |
redhat enterprise Linux workstation | =6.0 | |
redhat enterprise Linux workstation | =7.0 | |
openSUSE | =15.0 | |
openSUSE | =42.3 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =18.10 | |
Ubuntu Linux | =19.10 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Trellix ePolicy Orchestrator | =5.9.0 | |
Trellix ePolicy Orchestrator | =5.9.1 | |
Trellix ePolicy Orchestrator | =5.10.0 | |
hp xp7 command view | <8.6.5-00 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update211 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update201 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update202 | |
Oracle Java Runtime Environment (JRE) | =11.0.2 | |
Oracle Java Runtime Environment (JRE) | =12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2602 is a vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries).
The severity of CVE-2019-2602 is high with a CVSS score of 7.5.
The affected versions are Java SE: 7u211, 8u202, 11.0.2, and 12; Java SE Embedded: 8u201.
To fix CVE-2019-2602, update to the latest version of Oracle Java SE or Java SE Embedded.
You can find more information about CVE-2019-2602 on the Oracle and Red Hat security advisories.