Information disclosure in Oracle Java SE and Java SE Embedded - CVE-2019-2426

 

Information disclosure in Oracle Java SE and Java SE Embedded - CVE-2019-2426

Published: January 17, 2019


Vulnerability identifier: #VU17050
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-2426
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The weakness exists due to unspecified flaw in Networking component. A remote attacker read arbitrary data.

Affected software

Oracle Java SE
Java SE Embedded
IBM Java SDK
Gentoo Linux
Opensuse
IBM Cloud Transformation Advisor
IBM Decision Optimization for Cloud Pak for Data
IBM Tivoli System Automation Application Manager
EMC Data Protection Advisor
Dell EMC Data Protection Search
openjdk8 (Alpine package)
EMC Integrated Data Protection Appliance
Data Computing Appliance (DCA)
Tivoli System Automation for Multiplatforms
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2019-2426

Install update from vendor's website.

IBM Cloud Transformation Advisor - update to 1.9.8
openjdk8 (Alpine package) - update to 8.201.08-r0
IBM Decision Optimization for Cloud Pak for Data - update to 2.0
EMC Integrated Data Protection Appliance - update to 2.3
Data Computing Appliance (DCA) - update to 3.5.3.0
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.1.0.11, 4.1.0.2.0.1
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.3.0.8, 4.1.0.4.0.5
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
EMC Data Protection Advisor - addressed in versions 6.5 patch 136, 18.1 patch 74, 18.2 patch 26
IBM Java SDK - update to 8.0-5.30
Dell EMC Data Protection Search - update to 18.2.1

External References

Related Security Bulletins