CVE-2019-2821 is a medium-severity vulnerability in the Java SE component (JSSE subcomponent) affecting Java SE versions 11.0.3 and 12.0.1. This vulnerability allows an unauthenticated attacker with network access via TLS to gain unauthorized access to critical or all Java SE accessible data. Exploitation is difficult, requires human interaction, and primarily impacts client-side Java deployments running untrusted code. There is no known exploit code available, and it has not been observed in active exploitation, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0.3CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:11.0.3:*:*:*:*:*:*:* | ||
12.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:12.0.1:*:*:*:*:*:*:* | ||
11.0.3CPE matchmatch criteria | cpe:2.3:a:oracle:jre:11.0.3:*:*:*:*:*:*:* | ||
12.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:jre:12.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.