CVE-2019-17359: Apache Tomee

High severity, CVSS 7.5. EPSS: 9% chance of exploitation in the next 30 days.

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.

Affected products

  • Apache Tomee: version 7.0.7 only; version 7.1.2 only; version 8.0.1 only
  • Bouncycastle Bc-Java: version 1.63 only
  • Netapp Active Iq Unified Manager: from 7.3; from 9.5
  • Netapp Oncommand API Services: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Service Level Manager: affected versions not specified
  • Oracle Business Process Management Suite: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Communications Convergence: from 3.0.1.0, up to and including 3.0.2.1
  • Oracle Communications Diameter Signaling Router: from 8.0.0, up to and including 8.2.2
  • Oracle Communications Session Route Manager: from 8.2.0, up to and including 8.2.2
  • Oracle Data Integrator: version 12.2.1.4.0 only
  • Oracle Financial Services Analytical Applications Infrastructure: from 8.0.6, up to and including 8.0.9
  • Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
  • Oracle Hospitality Guest Access: version 4.2.0 only
  • Oracle Managed File Transfer: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle PeopleSoft Enterprise Hcm Global Payroll Switzerland: version 9.2 only
  • Oracle PeopleSoft Enterprise PeopleTools: version 8.56 only; version 8.57 only; version 8.58 only
  • Oracle Retail Xstore Point Of Service: version 18.0.1 only
  • Oracle Soa Suite: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Webcenter Portal: version 11.1.1.9.0 only; version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle WebLogic Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only

Published 2019-10-08. Last modified 2026-06-17.