CVE-2019-2996 is a medium-severity vulnerability affecting Oracle Java SE and Java SE Embedded (versions 8u221), specifically within the Deployment component. It allows an unauthenticated attacker with network access to compromise client-side Java deployments that run untrusted code, such as sandboxed Java Web Start applications or applets. Successful exploitation requires human interaction and can lead to unauthorized read, update, insert, or delete access to a subset of the affected system's data. The vulnerability has a CVSS 3.0 Base Score of 4.2, indicating a low impact on confidentiality and integrity. Its attack complexity is high, and user interaction is required, making it difficult to exploit. There is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.8.0:update221:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update221:*:*:*:*:*:* | ||
>= 11.0.0, <= 11.50.2CPE matchmatch criteria | cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:e-series_santricity_storage_manager:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:e-series_santricity_unified_manager:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.