Vulnerability Intelligence Report
CVE-2019-17195
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:11.03%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| connect2id | nimbus_jose\+jwt | all |
| apache | hadoop | 3.2.1 |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | 1.7.0 |
| oracle | communications_pricing_design_center | 12.0.0.3.0 |
| oracle | data_integrator | 12.2.1.4.0 |
| oracle | enterprise_manager_base_platform | 13.4.0.0 |
| oracle | healthcare_data_repository | 8.1.0 |
| oracle | insurance_policy_administration | all |
| oracle | jd_edwards_enterpriseone_orchestrator | all |
| oracle | jd_edwards_enterpriseone_tools | all |
| oracle | peoplesoft_enterprise_peopletools | 8.58, 8.59 |
| oracle | policy_automation | all |
| oracle | primavera_gateway | 19.12.0 |
| oracle | solaris_cluster | 4.0 |
| oracle | weblogic_server | 12.2.1.3.0, 12.2.1.4.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
11.032%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2019-10-05T00:00:00 |
| Published | 2019-10-15T13:42:34 |
| Last Updated | 2024-08-05T01:33:17 |
Community Chatter & Buzz