It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 6.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | no-centos-package-available | Aug 28, 2019 | Jul 31, 2019 |
| Debian | debian-upgrade-icedtea-web | Sep 11, 2019 | Jul 31, 2019 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-java-icedtea-web | Jul 26, 2021 | Jul 31, 2019 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-icedtea-web | Sep 16, 2021 | Jul 31, 2019 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-icedtea-web | Apr 30, 2021 | Jul 31, 2019 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-icedtea-web | Sep 12, 2019 | Jul 31, 2019 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-icedtea-web | Aug 31, 2020 | Jul 31, 2019 | |
| Oracle_linux | — | oracle-linux-upgrade-icedtea-weboracle-linux-upgrade-icedtea-web-develoracle-linux-upgrade-icedtea-web-javadoc | Jul 21, 2020 | Jul 31, 2019 |
| Redhat_linux | redhat-upgrade-icedtea-webredhat-upgrade-icedtea-web-debuginforedhat-upgrade-icedtea-web-develredhat-upgrade-icedtea-web-javadoc | Aug 1, 2019 | Jul 31, 2019 | |
| Suse | — | suse-upgrade-icedtea-websuse-upgrade-icedtea-web-javadoc | Aug 16, 2019 | Jul 31, 2019 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Jul 31, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub