It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 6.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | No Centos packages or updates have been released to address this issue | Aug 28, 2019 | Jul 31, 2019 |
| Debian | — | Upgrade icedtea-web | Sep 11, 2019 | Jul 31, 2019 |
| Gentoo Linux | — | Upgrade dev-java/icedtea-web. | Jul 26, 2021 | Jul 31, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade icedtea-web | Sep 16, 2021 | Jul 31, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade icedtea-web | Apr 30, 2021 | Jul 31, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade icedtea-web | Sep 12, 2019 | Jul 31, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade icedtea-web | Aug 31, 2020 | Jul 31, 2019 |
| Oracle_linux | — | Upgrade icedtea-web-develUpgrade icedtea-web-javadocUpgrade icedtea-web | Jul 21, 2020 | Jul 31, 2019 |
| Redhat_linux | — | Upgrade icedtea-web-develUpgrade icedtea-webNo solution existsUpgrade icedtea-web-debuginfoUpgrade icedtea-web-javadoc | Aug 1, 2019 | Jul 31, 2019 |
| Suse | — | Upgrade icedtea-web-javadocUpgrade icedtea-web | Aug 16, 2019 | Jul 31, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 31, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub