CVE-2019-17195: Apache Hadoop

Critical severity, CVSS 9.8. EPSS: 11.1% chance of exploitation in the next 30 days.

Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.

Affected products

  • Apache Hadoop: version 3.2.1 only
  • CONNECT2ID Nimbus Jose+jwt: before 7.9 (fixed in 7.9)
  • Oracle Communications Cloud Native Core Security Edge Protection Proxy: version 1.7.0 only
  • Oracle Communications Pricing Design Center: version 12.0.0.3.0 only
  • Oracle Data Integrator: version 12.2.1.4.0 only
  • Oracle Enterprise Manager Base Platform: version 13.4.0.0 only
  • Oracle Healthcare Data Repository: version 8.1.0 only
  • Oracle Insurance Policy Administration: from 11.0, up to and including 11.3.1
  • Oracle Jd Edwards Enterpriseone Orchestrator: up to and including 9.2.5.3
  • Oracle Jd Edwards Enterpriseone Tools: up to and including 9.2.5.3
  • Oracle PeopleSoft Enterprise PeopleTools: version 8.58 only; version 8.59 only
  • Oracle Policy Automation: from 12.2.0, up to and including 12.2.22
  • Oracle Primavera Gateway: from 18.8.0, up to and including 18.8.11; version 19.12.0 only
  • Oracle Solaris Cluster: version 4.0 only
  • Oracle WebLogic Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only

Published 2019-10-15. Last modified 2026-06-17.