Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-17195


Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.


Published

2019-10-15T14:15:12.380

Last Modified

2024-11-21T04:31:50.293

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-755

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application connect2id nimbus_jose\+jwt < 7.9 Yes
Application apache hadoop 3.2.1 Yes
Application oracle communications_cloud_native_core_security_edge_protection_proxy 1.7.0 Yes
Application oracle communications_pricing_design_center 12.0.0.3.0 Yes
Application oracle data_integrator 12.2.1.4.0 Yes
Application oracle enterprise_manager_base_platform 13.4.0.0 Yes
Application oracle healthcare_data_repository 8.1.0 Yes
Application oracle insurance_policy_administration ≤ 11.3.1 Yes
Application oracle jd_edwards_enterpriseone_orchestrator ≤ 9.2.5.3 Yes
Application oracle jd_edwards_enterpriseone_tools ≤ 9.2.5.3 Yes
Application oracle peoplesoft_enterprise_peopletools 8.58 Yes
Application oracle peoplesoft_enterprise_peopletools 8.59 Yes
Application oracle policy_automation ≤ 12.2.22 Yes
Application oracle primavera_gateway ≤ 18.8.11 Yes
Application oracle primavera_gateway 19.12.0 Yes
Application oracle solaris_cluster 4.0 Yes
Application oracle weblogic_server 12.2.1.3.0 Yes
Application oracle weblogic_server 12.2.1.4.0 Yes

References