CVE-2019-2602: High severity Oracle JDK vulnerability
A flaw was found in the BigDecimal implementation in the Libraries component of OpenJDK. An untrusted numeric value parsed by a Java application could the application to use an excessive amount of CPU time.
Other sources
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-2602?
CVE-2019-2602 is a vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries).
What is the severity of CVE-2019-2602?
The severity of CVE-2019-2602 is high with a CVSS score of 7.5.
Which versions of Java SE and Java SE Embedded are affected by CVE-2019-2602?
The affected versions are Java SE: 7u211, 8u202, 11.0.2, and 12; Java SE Embedded: 8u201.
How can I fix CVE-2019-2602?
To fix CVE-2019-2602, update to the latest version of Oracle Java SE or Java SE Embedded.
Where can I find more information about CVE-2019-2602?
You can find more information about CVE-2019-2602 on the Oracle and Red Hat security advisories.