peter bassill · operator
$ cve CVE-2019-17195 JSON

CVE-2019-17195

9.8
CRITICAL · CVSS 3.1 · EPSS 11.1% (pctl 96)

Patch early

EPSS 11.1% — above the 10% action threshold.

Description

Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS11.12% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-755
On CISA KEVno
Public exploitnone known
Published2019-10-15
Last modified2026-06-17

Affected (15)

VendorProduct
apachehadoop
connect2idnimbus jose\+jwt
oraclecommunications cloud native core security edge protection proxy
oraclecommunications pricing design center
oracledata integrator
oracleenterprise manager base platform
oraclehealthcare data repository
oracleinsurance policy administration
oraclejd edwards enterpriseone orchestrator
oraclejd edwards enterpriseone tools
oraclepeoplesoft enterprise peopletools
oraclepolicy automation
oracleprimavera gateway
oraclesolaris cluster
oracleweblogic server

References

→ the Explorer  ·  watch your stack  ·  NVD