← Back to CVE List
Vulnerability Intelligence Report

CVE-2019-17195

Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:11.03%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
connect2id nimbus_jose\+jwt all
apache hadoop 3.2.1
oracle communications_cloud_native_core_security_edge_protection_proxy 1.7.0
oracle communications_pricing_design_center 12.0.0.3.0
oracle data_integrator 12.2.1.4.0
oracle enterprise_manager_base_platform 13.4.0.0
oracle healthcare_data_repository 8.1.0
oracle insurance_policy_administration all
oracle jd_edwards_enterpriseone_orchestrator all
oracle jd_edwards_enterpriseone_tools all
oracle peoplesoft_enterprise_peopletools 8.58, 8.59
oracle policy_automation all
oracle primavera_gateway 19.12.0
oracle solaris_cluster 4.0
oracle weblogic_server 12.2.1.3.0, 12.2.1.4.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
11.032%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-10-05T00:00:00
Published2019-10-15T13:42:34
Last Updated2024-08-05T01:33:17

LINK COPIED TO CLIPBOARD