CVE-2019-10182: Icedtea-Web Project Icedtea-Web

Medium severity, CVSS 6.5. EPSS: 2.7% chance of exploitation in the next 30 days.

It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.

Affected products

  • Icedtea-Web Project Icedtea-Web: up to and including 1.7.2; version 1.8.2 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.6 only
  • Red Hat Enterprise Linux Server Eus: version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2019-07-31. Last modified 2026-06-17.