First published: Mon Oct 14 2019(Updated: )
Created from Advisory: ADV0024179
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-openjdk-1:1.8.0.232.b09-1.el6_10 | 1.8.0-openjdk-1:1.8.0.232.b09-1.el6_10 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el6_10 | 1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el6_10 |
redhat/java | <11-openjdk-1:11.0.5.10-0.el7_7 | 11-openjdk-1:11.0.5.10-0.el7_7 |
redhat/java | <1.8.0-openjdk-1:1.8.0.232.b09-0.el7_7 | 1.8.0-openjdk-1:1.8.0.232.b09-0.el7_7 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el7 | 1.8.0-ibm-1:1.8.0.6.10-1jpp.1.el7 |
redhat/java | <1.8.0-openjdk-1:1.8.0.232.b09-0.el8_0 | 1.8.0-openjdk-1:1.8.0.232.b09-0.el8_0 |
redhat/java | <11-openjdk-1:11.0.5.10-0.el8_0 | 11-openjdk-1:11.0.5.10-0.el8_0 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.10-1.el8_2 | 1.8.0-ibm-1:1.8.0.6.10-1.el8_2 |
IBM Engineering Requirements Quality Assistant On-Premises | <=All | |
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.25~5ea-1 | |
debian/openjdk-8 | 8u422-b05-1 | |
Oracle JDK 6 | =1.7.0-update231 | |
Oracle JDK 6 | =1.8.0-update221 | |
Oracle JDK 6 | =11.0.4 | |
Oracle JDK 6 | =13.0.0 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update231 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update221 | |
Oracle Java Runtime Environment (JRE) | =11.0.4 | |
Oracle Java Runtime Environment (JRE) | =13.0.0 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 | |
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.50.2 | |
netapp e-series santricity storage manager | ||
netapp e-series santricity unified manager | ||
NetApp E-Series SANtricity Web Services Proxy | ||
NetApp OnCommand Workflow Automation | ||
netapp snapmanager Oracle | ||
netapp snapmanager sap | ||
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux workstation | =6.0 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.04 | |
Ubuntu Linux | =19.10 | |
openSUSE | =15.0 | |
openSUSE | =15.1 | |
Trellix ePolicy Orchestrator | =5.9.0 | |
Trellix ePolicy Orchestrator | =5.9.1 | |
Trellix ePolicy Orchestrator | =5.10.0 | |
Trellix ePolicy Orchestrator | =5.10.0-update_1 | |
Trellix ePolicy Orchestrator | =5.10.0-update_2 | |
Trellix ePolicy Orchestrator | =5.10.0-update_3 | |
Trellix ePolicy Orchestrator | =5.10.0-update_4 | |
Trellix ePolicy Orchestrator | =5.10.0-update_5 | |
Trellix ePolicy Orchestrator | =5.10.0-update_6 | |
Debian | =8.0 | |
Debian | =9.0 | |
Debian | =10.0 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 | |
Ubuntu | =19.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2019-2949 refers to an unspecified vulnerability in Java SE related to the Kerberos component.
Java SE versions 7u231, 8u221, 11.0.4, and 13 are affected by CVE-2019-2949.
CVE-2019-2949 has a severity rating of 6.8 (high).
An unauthenticated attacker with network access can exploit CVE-2019-2949 via Kerberos.
You can find more information about CVE-2019-2949 at the following references: [Oracle Security Alert](https://www.oracle.com/security-alerts/cpuoct2019.html#AppendixJAVA), [Red Hat Security Advisory RHSA-2019:3128](https://access.redhat.com/errata/RHSA-2019:3128), [Red Hat Security Advisory RHSA-2019:3127](https://access.redhat.com/errata/RHSA-2019:3127).