CVE-2019-2989 is a medium-severity vulnerability in the Networking component of Oracle Java SE and Java SE Embedded, affecting versions 7u231, 8u221, 11.0.4, and 13. An unauthenticated attacker with network access can exploit this vulnerability with high attack complexity to achieve unauthorized data modification or deletion. While not actively exploited in the wild, this vulnerability has no known public exploit code and has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
19.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:19.2.0:*:*:*:enterprise:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update231:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update221:*:*:*:*:*:* | ||
11.0.4CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:11.0.4:*:*:*:*:*:*:* | ||
13.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:13.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.