CVE-2019-17195
CRITICALConnect2id Nimbus Jose+jwt < 7.9 - Improper Exception Handling
Title source: ruleDescription
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
Exploits (1)
References (16)
Scores
CVSS v3
9.8
EPSS
0.0535
EPSS Percentile
89.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-755
Status
published
Affected Products (19)
connect2id/nimbus_jose\+jwt
< 7.9
apache/hadoop
oracle/communications_cloud_native_core_security_edge_protection_proxy
oracle/communications_pricing_design_center
oracle/data_integrator
oracle/enterprise_manager_base_platform
oracle/healthcare_data_repository
oracle/insurance_policy_administration
< 11.3.1
oracle/jd_edwards_enterpriseone_orchestrator
< 9.2.5.3
oracle/jd_edwards_enterpriseone_tools
< 9.2.5.3
oracle/peoplesoft_enterprise_peopletools
oracle/peoplesoft_enterprise_peopletools
oracle/policy_automation
< 12.2.22
oracle/primavera_gateway
< 18.8.11
oracle/primavera_gateway
... and 4 more
Timeline
Published
Oct 15, 2019
Tracked Since
Feb 18, 2026