First published: Fri Oct 11 2019(Updated: )
An unspecified vulnerability in Java SE related to the Concurrency component could allow an unauthenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-openjdk-1:1.8.0.232.b09-1.el6_10 | 1.8.0-openjdk-1:1.8.0.232.b09-1.el6_10 |
redhat/java | <1.7.0-openjdk-1:1.7.0.241-2.6.20.0.el6_10 | 1.7.0-openjdk-1:1.7.0.241-2.6.20.0.el6_10 |
redhat/java | <1.7.1-ibm-1:1.7.1.4.55-1jpp.1.el6_10 | 1.7.1-ibm-1:1.7.1.4.55-1jpp.1.el6_10 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10 | 1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10 |
redhat/java | <11-openjdk-1:11.0.5.10-0.el7_7 | 11-openjdk-1:11.0.5.10-0.el7_7 |
redhat/java | <1.8.0-openjdk-1:1.8.0.232.b09-0.el7_7 | 1.8.0-openjdk-1:1.8.0.232.b09-0.el7_7 |
redhat/java | <1.7.0-openjdk-1:1.7.0.241-2.6.20.0.el7_7 | 1.7.0-openjdk-1:1.7.0.241-2.6.20.0.el7_7 |
redhat/java | <1.7.1-ibm-1:1.7.1.4.55-1jpp.1.el7 | 1.7.1-ibm-1:1.7.1.4.55-1jpp.1.el7 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el7 | 1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el7 |
redhat/java | <1.8.0-openjdk-1:1.8.0.232.b09-0.el8_0 | 1.8.0-openjdk-1:1.8.0.232.b09-0.el8_0 |
redhat/java | <11-openjdk-1:11.0.5.10-0.el8_0 | 11-openjdk-1:11.0.5.10-0.el8_0 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.0-3.el8_1 | 1.8.0-ibm-1:1.8.0.6.0-3.el8_1 |
IBM Engineering Requirements Quality Assistant On-Premises | <=All | |
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.25~5ea-1 | |
debian/openjdk-8 | 8u422-b05-1 | |
Oracle JDK 6 | =1.7.0-update231 | |
Oracle JDK 6 | =1.8.0-update221 | |
Oracle JDK 6 | =11.0.4 | |
Oracle JDK 6 | =13.0.0 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update231 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update221 | |
Oracle Java Runtime Environment (JRE) | =11.0.4 | |
Oracle Java Runtime Environment (JRE) | =13.0.0 | |
redhat satellite | =5.8 | |
Red Hat Enterprise Linux | =8.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux eus | =7.7 | |
redhat enterprise Linux eus | =8.6 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux server aus | =7.7 | |
redhat enterprise Linux server tus | =7.7 | |
redhat enterprise Linux workstation | =6.0 | |
redhat enterprise Linux workstation | =7.0 | |
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.50.2 | |
netapp e-series santricity storage manager | ||
netapp e-series santricity unified manager | ||
NetApp E-Series SANtricity Web Services Proxy | ||
NetApp OnCommand Workflow Automation | ||
netapp snapmanager Oracle | ||
netapp snapmanager sap | ||
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 | |
openSUSE | =15.0 | |
openSUSE | =15.1 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.04 | |
Ubuntu Linux | =19.10 | |
Debian | =8.0 | |
Debian | =9.0 | |
Debian | =10.0 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 | |
Ubuntu | =19.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The severity of CVE-2019-2964 is low with a severity value of 3.7.
CVE-2019-2964 is a vulnerability in the Concurrency component of Java SE, which could allow an unauthenticated attacker with network access to exploit the system.
Java SE versions 7u231, 8u221, 11.0.4, and 13 are affected by CVE-2019-2964.
To fix CVE-2019-2964, update Java SE to versions 7u231, 8u221, 11.0.4, or 13.
You can find more information about CVE-2019-2964 on Oracle's security alerts page and Red Hat's errata pages.