OpenJDK Vulnerability Advisory: 2019/4/16

The following vulnerabilities in OpenJDK source code were fixed in this release. The affected versions are 12, 11.0.2, 8u202, 7u211, and earlier. We recommend that you upgrade as soon as possible.

The current and previous advisories are available for reference.

Risk matrix

Affects ...
CVE ID Component CVSSv3
Vector
7 8 11 12
CVE-2019-2697 client-libs/
2d
8.1
NHNNUHHH
CVE-2019-2698 client-libs/
2d
8.1
NHNNUHHH
CVE-2019-2602 core-libs/
java.math
7.5
NLNNUNNH
CVE-2019-2684 core-libs/
java.rmi
5.9
NHNNUNHN

Acknowledgements

We acknowledge the following parties for their reports and contributions: Corwin De Boor, Mateusz Jurczyk (Google Project Zero), and Robert Xiao.

We also thank the Leads of the JDK 7 Updates, JDK 8 Updates, and JDK 11 Updates Projects for providing the risk-matrix information for their releases.

How to report a vulnerability

Please see the reporting instructions for information about how to report a vulnerability.

Last update: 2019/7/17 21:00 UTC