CVE-2019-2989: XSS
An unspecified vulnerability in Java SE could allow an unauthenticated attacker to cause no confidentiality impact, high integrity impact, and no availability impact.
Other sources
It was discovered that the HttpURLConnection class in the Networking component in OpenJDK did not properly handle certain responses from HTTP proxies. A malicious HTTP proxy server could possibly use this flaw to inject content into the proxied connection even when using TLS connections.
— Red Hat
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS v3.0 Base Score 6.8 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N).
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-2989?
CVE-2019-2989 is an unspecified vulnerability in Java SE that could allow an unauthenticated attacker to cause no confidence.
Which versions of Java SE are affected by CVE-2019-2989?
The affected versions of Java SE are 7u231, 8u221, 11.0.4, and 13.
Which versions of Java SE Embedded are affected by CVE-2019-2989?
The affected version of Java SE Embedded is 8u221.
How do I fix CVE-2019-2989?
To fix CVE-2019-2989, update your Java SE to version 7u241, 8u231, 11.0.5, or 13.0.1.
Where can I find more information about CVE-2019-2989?
More information about CVE-2019-2989 can be found on the Oracle Security Alerts page and the Red Hat Errata page.