CVE-2019-10182: Icedtea-Web Project Icedtea-Web
Medium severity, CVSS 6.5. EPSS: 2.7% chance of exploitation in the next 30 days.
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.
Affected products
- Icedtea-Web Project Icedtea-Web: up to and including 1.7.2; version 1.8.2 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.6 only
- Red Hat Enterprise Linux Server Eus: version 7.6 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2019-07-31. Last modified 2026-06-17.