CVE-2019-17195
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
Published:Oct 15, 2019
Last Modified:Nov 21, 2024
EPS:Oct 15, 2019
EPSS Score:0.11339
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Apache
Product
Hadoop
Apache
Hadoop
Vendor
Connect2id
Product
Nimbus Jose\+jwt
Connect2id
Nimbus Jose\+jwt
Vendor
Oracle
Product
Communications Cloud Native Core Security Edge Protection Proxy
Oracle
Communications Cloud Native Core Security Edge Protection Proxy
Vendor
Oracle
Product
Communications Pricing Design Center
Oracle
Communications Pricing Design Center
Vendor
Oracle
Product
Data Integrator
Oracle
Data Integrator
Vendor
Oracle
Product
Enterprise Manager Base Platform
Oracle
Enterprise Manager Base Platform
Vendor
Oracle
Product
Healthcare Data Repository
Oracle
Healthcare Data Repository
Vendor
Oracle
Product
Insurance Policy Administration
Oracle
Insurance Policy Administration
Vendor
Oracle
Product
Jd Edwards Enterpriseone Orchestrator
Oracle
Jd Edwards Enterpriseone Orchestrator
Vendor
Oracle
Product
Jd Edwards Enterpriseone Tools
Oracle
Jd Edwards Enterpriseone Tools
Vendor
Oracle
Product
Peoplesoft Enterprise Peopletools
Oracle
Peoplesoft Enterprise Peopletools
Vendor
Oracle
Product
Policy Automation
Oracle
Policy Automation
Vendor
Oracle
Product
Primavera Gateway
Oracle
Primavera Gateway
Vendor
Oracle
Product
Solaris Cluster
Oracle
Solaris Cluster
Vendor
Oracle
Product
Weblogic Server
Oracle
Weblogic Server
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Redhat
Product
Rhev Manager
Redhat
Rhev Manager
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
