Vulnerability Details CVE-2019-2684
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 81.9%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
Products affected by CVE-2019-2684
-
cpe:2.3:a:apache:cassandra:2.1.0
-
cpe:2.3:a:apache:cassandra:2.1.1
-
cpe:2.3:a:apache:cassandra:2.1.12
-
cpe:2.3:a:apache:cassandra:2.1.13
-
cpe:2.3:a:apache:cassandra:2.1.14
-
cpe:2.3:a:apache:cassandra:2.1.15
-
cpe:2.3:a:apache:cassandra:2.1.16
-
cpe:2.3:a:apache:cassandra:2.1.17
-
cpe:2.3:a:apache:cassandra:2.1.18
-
cpe:2.3:a:apache:cassandra:2.1.19
-
cpe:2.3:a:apache:cassandra:2.1.2
-
cpe:2.3:a:apache:cassandra:2.1.20
-
cpe:2.3:a:apache:cassandra:2.1.21
-
cpe:2.3:a:apache:cassandra:2.1.3
-
cpe:2.3:a:apache:cassandra:2.1.4
-
cpe:2.3:a:apache:cassandra:2.1.5
-
cpe:2.3:a:apache:cassandra:2.1.6
-
cpe:2.3:a:apache:cassandra:2.1.7
-
cpe:2.3:a:apache:cassandra:2.1.8
-
cpe:2.3:a:apache:cassandra:2.1.9
-
cpe:2.3:a:apache:cassandra:2.2.0
-
cpe:2.3:a:apache:cassandra:2.2.1
-
cpe:2.3:a:apache:cassandra:2.2.10
-
cpe:2.3:a:apache:cassandra:2.2.11
-
cpe:2.3:a:apache:cassandra:2.2.12
-
cpe:2.3:a:apache:cassandra:2.2.13
-
cpe:2.3:a:apache:cassandra:2.2.14
-
cpe:2.3:a:apache:cassandra:2.2.15
-
cpe:2.3:a:apache:cassandra:2.2.16
-
cpe:2.3:a:apache:cassandra:2.2.17
-
cpe:2.3:a:apache:cassandra:3.0.0
-
cpe:2.3:a:apache:cassandra:3.0.1
-
cpe:2.3:a:apache:cassandra:3.0.10
-
cpe:2.3:a:apache:cassandra:3.0.11
-
cpe:2.3:a:apache:cassandra:3.0.12
-
cpe:2.3:a:apache:cassandra:3.0.13
-
cpe:2.3:a:apache:cassandra:3.0.14
-
cpe:2.3:a:apache:cassandra:3.0.15
-
cpe:2.3:a:apache:cassandra:3.0.16
-
cpe:2.3:a:apache:cassandra:3.0.17
-
cpe:2.3:a:apache:cassandra:3.0.18
-
cpe:2.3:a:apache:cassandra:3.0.19
-
cpe:2.3:a:apache:cassandra:3.0.2
-
cpe:2.3:a:apache:cassandra:3.0.20
-
cpe:2.3:a:apache:cassandra:3.0.21
-
cpe:2.3:a:apache:cassandra:3.0.3
-
cpe:2.3:a:apache:cassandra:3.0.4
-
cpe:2.3:a:apache:cassandra:3.0.5
-
cpe:2.3:a:apache:cassandra:3.0.6
-
cpe:2.3:a:apache:cassandra:3.0.7
-
cpe:2.3:a:apache:cassandra:3.0.8
-
cpe:2.3:a:apache:cassandra:3.0.9
-
cpe:2.3:a:apache:cassandra:3.11.0
-
cpe:2.3:a:apache:cassandra:3.11.1
-
cpe:2.3:a:apache:cassandra:3.11.2
-
cpe:2.3:a:apache:cassandra:3.11.3
-
cpe:2.3:a:apache:cassandra:3.11.4
-
cpe:2.3:a:apache:cassandra:3.11.5
-
cpe:2.3:a:apache:cassandra:3.11.6
-
cpe:2.3:a:apache:cassandra:3.11.7
-
cpe:2.3:a:apache:cassandra:4.0.0
-
cpe:2.3:a:apache:tomcat:7.0.0
-
cpe:2.3:a:apache:tomcat:7.0.1
-
cpe:2.3:a:apache:tomcat:7.0.10
-
cpe:2.3:a:apache:tomcat:7.0.11
-
cpe:2.3:a:apache:tomcat:7.0.12
-
cpe:2.3:a:apache:tomcat:7.0.13
-
cpe:2.3:a:apache:tomcat:7.0.14
-
cpe:2.3:a:apache:tomcat:7.0.15
-
cpe:2.3:a:apache:tomcat:7.0.16
-
cpe:2.3:a:apache:tomcat:7.0.17
-
cpe:2.3:a:apache:tomcat:7.0.18
-
cpe:2.3:a:apache:tomcat:7.0.19
-
cpe:2.3:a:apache:tomcat:7.0.2
-
cpe:2.3:a:apache:tomcat:7.0.20
-
cpe:2.3:a:apache:tomcat:7.0.21
-
cpe:2.3:a:apache:tomcat:7.0.22
-
cpe:2.3:a:apache:tomcat:7.0.23
-
cpe:2.3:a:apache:tomcat:7.0.24
-
cpe:2.3:a:apache:tomcat:7.0.25
-
cpe:2.3:a:apache:tomcat:7.0.26
-
cpe:2.3:a:apache:tomcat:7.0.27
-
cpe:2.3:a:apache:tomcat:7.0.28
-
cpe:2.3:a:apache:tomcat:7.0.29
-
cpe:2.3:a:apache:tomcat:7.0.3
-
cpe:2.3:a:apache:tomcat:7.0.30
-
cpe:2.3:a:apache:tomcat:7.0.31
-
cpe:2.3:a:apache:tomcat:7.0.32
-
cpe:2.3:a:apache:tomcat:7.0.33
-
cpe:2.3:a:apache:tomcat:7.0.34
-
cpe:2.3:a:apache:tomcat:7.0.35
-
cpe:2.3:a:apache:tomcat:7.0.36
-
cpe:2.3:a:apache:tomcat:7.0.37
-
cpe:2.3:a:apache:tomcat:7.0.38
-
cpe:2.3:a:apache:tomcat:7.0.39
-
cpe:2.3:a:apache:tomcat:7.0.4
-
cpe:2.3:a:apache:tomcat:7.0.40
-
cpe:2.3:a:apache:tomcat:7.0.41
-
cpe:2.3:a:apache:tomcat:7.0.42
-
cpe:2.3:a:apache:tomcat:7.0.43
-
cpe:2.3:a:apache:tomcat:7.0.44
-
cpe:2.3:a:apache:tomcat:7.0.45
-
cpe:2.3:a:apache:tomcat:7.0.46
-
cpe:2.3:a:apache:tomcat:7.0.47
-
cpe:2.3:a:apache:tomcat:7.0.48
-
cpe:2.3:a:apache:tomcat:7.0.49
-
cpe:2.3:a:apache:tomcat:7.0.5
-
cpe:2.3:a:apache:tomcat:7.0.50
-
cpe:2.3:a:apache:tomcat:7.0.51
-
cpe:2.3:a:apache:tomcat:7.0.52
-
cpe:2.3:a:apache:tomcat:7.0.53
-
cpe:2.3:a:apache:tomcat:7.0.54
-
cpe:2.3:a:apache:tomcat:7.0.55
-
cpe:2.3:a:apache:tomcat:7.0.56
-
cpe:2.3:a:apache:tomcat:7.0.57
-
cpe:2.3:a:apache:tomcat:7.0.58
-
cpe:2.3:a:apache:tomcat:7.0.59
-
cpe:2.3:a:apache:tomcat:7.0.6
-
cpe:2.3:a:apache:tomcat:7.0.60
-
cpe:2.3:a:apache:tomcat:7.0.61
-
cpe:2.3:a:apache:tomcat:7.0.62
-
cpe:2.3:a:apache:tomcat:7.0.63
-
cpe:2.3:a:apache:tomcat:7.0.64
-
cpe:2.3:a:apache:tomcat:7.0.65
-
cpe:2.3:a:apache:tomcat:7.0.66
-
cpe:2.3:a:apache:tomcat:7.0.67
-
cpe:2.3:a:apache:tomcat:7.0.68
-
cpe:2.3:a:apache:tomcat:7.0.69
-
cpe:2.3:a:apache:tomcat:7.0.7
-
cpe:2.3:a:apache:tomcat:7.0.70
-
cpe:2.3:a:apache:tomcat:7.0.71
-
cpe:2.3:a:apache:tomcat:7.0.72
-
cpe:2.3:a:apache:tomcat:7.0.73
-
cpe:2.3:a:apache:tomcat:7.0.74
-
cpe:2.3:a:apache:tomcat:7.0.75
-
cpe:2.3:a:apache:tomcat:7.0.76
-
cpe:2.3:a:apache:tomcat:7.0.77
-
cpe:2.3:a:apache:tomcat:7.0.78
-
cpe:2.3:a:apache:tomcat:7.0.79
-
cpe:2.3:a:apache:tomcat:7.0.8
-
cpe:2.3:a:apache:tomcat:7.0.80
-
cpe:2.3:a:apache:tomcat:7.0.81
-
cpe:2.3:a:apache:tomcat:7.0.82
-
cpe:2.3:a:apache:tomcat:7.0.83
-
cpe:2.3:a:apache:tomcat:7.0.84
-
cpe:2.3:a:apache:tomcat:7.0.85
-
cpe:2.3:a:apache:tomcat:7.0.86
-
cpe:2.3:a:apache:tomcat:7.0.87
-
cpe:2.3:a:apache:tomcat:7.0.88
-
cpe:2.3:a:apache:tomcat:7.0.89
-
cpe:2.3:a:apache:tomcat:7.0.9
-
cpe:2.3:a:apache:tomcat:7.0.90
-
cpe:2.3:a:apache:tomcat:7.0.91
-
cpe:2.3:a:apache:tomcat:7.0.92
-
cpe:2.3:a:apache:tomcat:7.0.93
-
cpe:2.3:a:apache:tomcat:7.0.94
-
cpe:2.3:a:apache:tomcat:7.0.95
-
cpe:2.3:a:apache:tomcat:7.0.96
-
cpe:2.3:a:apache:tomcat:7.0.97
-
cpe:2.3:a:apache:tomcat:8.5.0
-
cpe:2.3:a:apache:tomcat:8.5.1
-
cpe:2.3:a:apache:tomcat:8.5.10
-
cpe:2.3:a:apache:tomcat:8.5.11
-
cpe:2.3:a:apache:tomcat:8.5.12
-
cpe:2.3:a:apache:tomcat:8.5.13
-
cpe:2.3:a:apache:tomcat:8.5.14
-
cpe:2.3:a:apache:tomcat:8.5.15
-
cpe:2.3:a:apache:tomcat:8.5.16
-
cpe:2.3:a:apache:tomcat:8.5.17
-
cpe:2.3:a:apache:tomcat:8.5.18
-
cpe:2.3:a:apache:tomcat:8.5.19
-
cpe:2.3:a:apache:tomcat:8.5.2
-
cpe:2.3:a:apache:tomcat:8.5.20
-
cpe:2.3:a:apache:tomcat:8.5.21
-
cpe:2.3:a:apache:tomcat:8.5.22
-
cpe:2.3:a:apache:tomcat:8.5.23
-
cpe:2.3:a:apache:tomcat:8.5.24
-
cpe:2.3:a:apache:tomcat:8.5.25
-
cpe:2.3:a:apache:tomcat:8.5.26
-
cpe:2.3:a:apache:tomcat:8.5.27
-
cpe:2.3:a:apache:tomcat:8.5.28
-
cpe:2.3:a:apache:tomcat:8.5.29
-
cpe:2.3:a:apache:tomcat:8.5.3
-
cpe:2.3:a:apache:tomcat:8.5.30
-
cpe:2.3:a:apache:tomcat:8.5.31
-
cpe:2.3:a:apache:tomcat:8.5.32
-
cpe:2.3:a:apache:tomcat:8.5.33
-
cpe:2.3:a:apache:tomcat:8.5.34
-
cpe:2.3:a:apache:tomcat:8.5.35
-
cpe:2.3:a:apache:tomcat:8.5.36
-
cpe:2.3:a:apache:tomcat:8.5.37
-
cpe:2.3:a:apache:tomcat:8.5.38
-
cpe:2.3:a:apache:tomcat:8.5.39
-
cpe:2.3:a:apache:tomcat:8.5.4
-
cpe:2.3:a:apache:tomcat:8.5.40
-
cpe:2.3:a:apache:tomcat:8.5.41
-
cpe:2.3:a:apache:tomcat:8.5.42
-
cpe:2.3:a:apache:tomcat:8.5.43
-
cpe:2.3:a:apache:tomcat:8.5.44
-
cpe:2.3:a:apache:tomcat:8.5.45
-
cpe:2.3:a:apache:tomcat:8.5.46
-
cpe:2.3:a:apache:tomcat:8.5.47
-
cpe:2.3:a:apache:tomcat:8.5.5
-
cpe:2.3:a:apache:tomcat:8.5.6
-
cpe:2.3:a:apache:tomcat:8.5.7
-
cpe:2.3:a:apache:tomcat:8.5.8
-
cpe:2.3:a:apache:tomcat:8.5.9
-
cpe:2.3:a:apache:tomcat:9.0.0
-
cpe:2.3:a:apache:tomcat:9.0.1
-
cpe:2.3:a:apache:tomcat:9.0.10
-
cpe:2.3:a:apache:tomcat:9.0.11
-
cpe:2.3:a:apache:tomcat:9.0.12
-
cpe:2.3:a:apache:tomcat:9.0.13
-
cpe:2.3:a:apache:tomcat:9.0.14
-
cpe:2.3:a:apache:tomcat:9.0.15
-
cpe:2.3:a:apache:tomcat:9.0.16
-
cpe:2.3:a:apache:tomcat:9.0.17
-
cpe:2.3:a:apache:tomcat:9.0.18
-
cpe:2.3:a:apache:tomcat:9.0.19
-
cpe:2.3:a:apache:tomcat:9.0.2
-
cpe:2.3:a:apache:tomcat:9.0.20
-
cpe:2.3:a:apache:tomcat:9.0.21
-
cpe:2.3:a:apache:tomcat:9.0.22
-
cpe:2.3:a:apache:tomcat:9.0.23
-
cpe:2.3:a:apache:tomcat:9.0.24
-
cpe:2.3:a:apache:tomcat:9.0.25
-
cpe:2.3:a:apache:tomcat:9.0.26
-
cpe:2.3:a:apache:tomcat:9.0.27
-
cpe:2.3:a:apache:tomcat:9.0.28
-
cpe:2.3:a:apache:tomcat:9.0.3
-
cpe:2.3:a:apache:tomcat:9.0.4
-
cpe:2.3:a:apache:tomcat:9.0.5
-
cpe:2.3:a:apache:tomcat:9.0.6
-
cpe:2.3:a:apache:tomcat:9.0.7
-
cpe:2.3:a:apache:tomcat:9.0.8
-
cpe:2.3:a:apache:tomcat:9.0.9
-
cpe:2.3:a:hp:xp7_command_view:-
-
cpe:2.3:a:hp:xp7_command_view:8.4.0
-
cpe:2.3:a:hp:xp7_command_view:8.4.1
-
cpe:2.3:a:hp:xp7_command_view:8.6.2-01
-
cpe:2.3:a:hp:xp7_command_view:8.6.3-00
-
cpe:2.3:a:hp:xp7_command_view:8.6.4-00
-
cpe:2.3:a:oracle:jdk:1.7.0
-
cpe:2.3:a:oracle:jdk:1.8.0
-
cpe:2.3:a:oracle:jdk:11.0.2
-
-
cpe:2.3:a:oracle:jre:1.7.0
-
cpe:2.3:a:oracle:jre:1.8.0
-
cpe:2.3:a:oracle:jre:11.0.2
-
-
cpe:2.3:a:redhat:openshift_container_platform:3.11
-
cpe:2.3:a:redhat:satellite:5.8
-
cpe:2.3:o:canonical:ubuntu_linux:16.04
-
cpe:2.3:o:canonical:ubuntu_linux:18.04
-
cpe:2.3:o:canonical:ubuntu_linux:18.10
-
cpe:2.3:o:canonical:ubuntu_linux:19.04
-
cpe:2.3:o:debian:debian_linux:8.0
-
cpe:2.3:o:debian:debian_linux:9.0
-
cpe:2.3:o:opensuse:leap:15.0
-
cpe:2.3:o:opensuse:leap:42.3
-
cpe:2.3:o:redhat:enterprise_linux:8.0
-
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0
-
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0
-
cpe:2.3:o:redhat:enterprise_linux_eus:8.1
-
cpe:2.3:o:redhat:enterprise_linux_eus:8.2
-
cpe:2.3:o:redhat:enterprise_linux_eus:8.4
-
cpe:2.3:o:redhat:enterprise_linux_eus:8.6
-
cpe:2.3:o:redhat:enterprise_linux_server:6.0
-
cpe:2.3:o:redhat:enterprise_linux_server:7.0
-
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2
-
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4
-
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6
-
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2
-
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4
-
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6
-
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0
-
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0