First published: Tue Oct 15 2019(Updated: )
An unspecified vulnerability in Java SE related to the Deployment component could allow an unauthenticated attacker to cause low confidentiality impact, low integrity impact, and no availability impact.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10 | 1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el6_10 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el7 | 1.8.0-ibm-1:1.8.0.6.0-1jpp.1.el7 |
redhat/java | <1.8.0-ibm-1:1.8.0.6.0-3.el8_1 | 1.8.0-ibm-1:1.8.0.6.0-3.el8_1 |
Oracle JDK | =1.8.0-update221 | |
Oracle JRE | =1.8.0-update221 | |
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.50.2 | |
Netapp E-series Santricity Storage Manager | ||
Netapp E-series Santricity Unified Manager | ||
Netapp E-series Santricity Web Services Proxy | ||
NetApp OnCommand Workflow Automation | ||
Netapp Snapmanager Oracle | ||
Netapp Snapmanager Sap | ||
Redhat Satellite | =5.8 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Eus | =8.1 | |
Redhat Enterprise Linux Eus | =8.6 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
IBM Engineering Requirements Quality Assistant On-Premises | <=All |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2019-2996 is a vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE that allows an unauthenticated attacker with network access to compromise the Java SE Deployment component.
CVE-2019-2996 has a severity level of medium (4) according to the Common Vulnerability Scoring System (CVSS).
The affected software versions are Java SE 8u221 and Java SE Embedded 8u221.
To fix CVE-2019-2996, update your Java SE or Java SE Embedded to version 8u221.
You can find more information about CVE-2019-2996 on the following references: [https://access.redhat.com/security/cve/CVE-2019-2996](https://access.redhat.com/security/cve/CVE-2019-2996), [https://www.oracle.com/security-alerts/cpuoct2019.html#AppendixJAVA](https://www.oracle.com/security-alerts/cpuoct2019.html#AppendixJAVA), [https://access.redhat.com/errata/RHSA-2019:4113](https://access.redhat.com/errata/RHSA-2019:4113)