CVE-2019-17195
15.10.2019, 14:15
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.Enginsight
| Vendor | Product | Version |
|---|---|---|
| connect2id | nimbus_jose\+jwt | 𝑥 < 7.9 |
| apache | hadoop | 3.2.1 |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | 1.7.0 |
| oracle | communications_pricing_design_center | 12.0.0.3.0 |
| oracle | data_integrator | 12.2.1.4.0 |
| oracle | enterprise_manager_base_platform | 13.4.0.0 |
| oracle | healthcare_data_repository | 8.1.0 |
| oracle | insurance_policy_administration | 11.0 ≤ 𝑥 ≤ 11.3.1 |
| oracle | jd_edwards_enterpriseone_orchestrator | 𝑥 ≤ 9.2.5.3 |
| oracle | jd_edwards_enterpriseone_tools | 𝑥 ≤ 9.2.5.3 |
| oracle | peoplesoft_enterprise_peopletools | 8.58 |
| oracle | peoplesoft_enterprise_peopletools | 8.59 |
| oracle | policy_automation | 12.2.0 ≤ 𝑥 ≤ 12.2.22 |
| oracle | primavera_gateway | 18.8.0 ≤ 𝑥 ≤ 18.8.11 |
| oracle | primavera_gateway | 19.12.0 |
| oracle | solaris_cluster | 4.0 |
| oracle | weblogic_server | 12.2.1.3.0 |
| oracle | weblogic_server | 12.2.1.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References