CVE-2019-17195
15.10.2019, 14:15
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.Enginsight
Vendor | Product | Version |
---|---|---|
connect2id | nimbus_jose\+jwt | 𝑥 < 7.9 |
apache | hadoop | 3.2.1 |
oracle | communications_cloud_native_core_security_edge_protection_proxy | 1.7.0 |
oracle | communications_pricing_design_center | 12.0.0.3.0 |
oracle | data_integrator | 12.2.1.4.0 |
oracle | enterprise_manager_base_platform | 13.4.0.0 |
oracle | healthcare_data_repository | 8.1.0 |
oracle | insurance_policy_administration | 11.0 ≤ 𝑥 ≤ 11.3.1 |
oracle | jd_edwards_enterpriseone_orchestrator | 𝑥 ≤ 9.2.5.3 |
oracle | jd_edwards_enterpriseone_tools | 𝑥 ≤ 9.2.5.3 |
oracle | peoplesoft_enterprise_peopletools | 8.58 |
oracle | peoplesoft_enterprise_peopletools | 8.59 |
oracle | policy_automation | 12.2.0 ≤ 𝑥 ≤ 12.2.22 |
oracle | primavera_gateway | 18.8.0 ≤ 𝑥 ≤ 18.8.11 |
oracle | primavera_gateway | 19.12.0 |
oracle | solaris_cluster | 4.0 |
oracle | weblogic_server | 12.2.1.3.0 |
oracle | weblogic_server | 12.2.1.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References