CVE-2019-17195

CRITICAL

Connect2id Nimbus Jose+jwt < 7.9 - Improper Exception Handling

Title source: rule

Description

Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.

Exploits (1)

nomisec SCANNER 12 stars
by somatrasss · poc
https://github.com/somatrasss/weblogic2021

References (16)

Scores

CVSS v3 9.8
EPSS 0.0535
EPSS Percentile 89.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-755
Status published

Affected Products (19)

connect2id/nimbus_jose\+jwt < 7.9
apache/hadoop
oracle/communications_cloud_native_core_security_edge_protection_proxy
oracle/communications_pricing_design_center
oracle/data_integrator
oracle/enterprise_manager_base_platform
oracle/healthcare_data_repository
oracle/insurance_policy_administration < 11.3.1
oracle/jd_edwards_enterpriseone_orchestrator < 9.2.5.3
oracle/jd_edwards_enterpriseone_tools < 9.2.5.3
oracle/peoplesoft_enterprise_peopletools
oracle/peoplesoft_enterprise_peopletools
oracle/policy_automation < 12.2.22
oracle/primavera_gateway < 18.8.11
oracle/primavera_gateway
... and 4 more

Timeline

Published Oct 15, 2019
Tracked Since Feb 18, 2026