---
title: "CVE-2019-2422\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-2422?format=md
keywords: index, follow
---

# CVE-2019-2422

Publication date 16 January 2019

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**3.1 · Low**

[Score breakdown](https://ubuntu.com/security/CVE-2019-2422?format=md#impact-score)

Toggle side navigation

## Description

Vulnerability in the Java SE component of Oracle Java SE (subcomponent:
Libraries). Supported versions that are affected are Java SE: 7u201, 8u192
and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability
allows unauthenticated attacker with network access via multiple protocols
to compromise Java SE. Successful attacks require human interaction from a
person other than the attacker. Successful attacks of this vulnerability
can result in unauthorized read access to a subset of Java SE accessible
data. Note: This vulnerability applies to Java deployments, typically in
clients running sandboxed Java Web Start applications or sandboxed Java
applets (in Java SE 8), that load and run untrusted code (e.g., code that
comes from the internet) and rely on the Java sandbox for security. This
vulnerability does not apply to Java deployments, typically in servers,
that load and run only trusted code (e.g., code installed by an
administrator). CVSS 3.0 Base Score 3.1 (Confidentiality impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).

### From the Ubuntu Security Team

It was discovered that a memory disclosure issue existed in the
OpenJDK Library subsystem. An attacker could use this to expose
sensitive information and possibly bypass Java sandbox restrictions.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openjdk-6 | 22.04 LTS jammy | Not in release |
| 21.10 impish | Not in release |
| 21.04 hirsute | Not in release |
| 20.10 groovy | Not in release |
| 20.04 LTS focal | Not in release |
| 19.10 eoan | Not in release |
| 19.04 disco | Not in release |
| 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| openjdk-7 | 22.04 LTS jammy | Not in release |
| 21.10 impish | Not in release |
| 21.04 hirsute | Not in release |
| 20.10 groovy | Not in release |
| 20.04 LTS focal | Not in release |
| 19.10 eoan | Not in release |
| 19.04 disco | Not in release |
| 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Fixed 7u211-2.6.17-0ubuntu0.1 |
| openjdk-8 | 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not affected |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Not affected |
| 19.04 disco | Fixed 8u191-b12-2ubuntu0.19.04.1 |
| 18.10 cosmic | Fixed 8u191-b12-2ubuntu0.18.10.1 |
| 18.04 LTS bionic | Fixed 8u191-b12-2ubuntu0.18.04.1 |
| 16.04 LTS xenial | Fixed 8u191-b12-2ubuntu0.16.04.1 |
| 14.04 LTS trusty | Not in release |
| openjdk-9 | 22.04 LTS jammy | Not in release |
| 21.10 impish | Not in release |
| 21.04 hirsute | Not in release |
| 20.10 groovy | Not in release |
| 20.04 LTS focal | Not in release |
| 19.10 eoan | Not in release |
| 19.04 disco | Not in release |
| 18.10 cosmic | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| openjdk-lts | 22.04 LTS jammy | Fixed 11.0.1+13-3ubuntu3.19.04.1 |
| 21.10 impish | Fixed 11.0.1+13-3ubuntu3.19.04.1 |
| 21.04 hirsute | Fixed 11.0.1+13-3ubuntu3.19.04.1 |
| 20.10 groovy | Fixed 11.0.1+13-3ubuntu3.19.04.1 |
| 20.04 LTS focal | Fixed 11.0.1+13-3ubuntu3.19.04.1 |
| 19.10 eoan | Fixed 11.0.1+13-3ubuntu3.19.04.1 |
| 19.04 disco | Fixed 11.0.1+13-3ubuntu3.19.04.1 |
| 18.10 cosmic | Fixed 11.0.1+13-3ubuntu3.18.10.1 |
| 18.04 LTS bionic | Fixed 11.0.2+9-3ubuntu1~18.04.3 |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

3.1 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 3.1 · Low |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2422)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-2422)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-2422)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-2422)

### Related Ubuntu Security Notices (USN)

+ [USN-3942-1](https://usn.ubuntu.com/USN-3942-1)
+ OpenJDK 7 vulnerability
+ 9 April 2019

+ [USN-3875-1](https://usn.ubuntu.com/USN-3875-1)
+ OpenJDK vulnerability
+ 30 January 2019

+ [USN-3949-1](https://usn.ubuntu.com/USN-3949-1)
+ OpenJDK 11 vulnerability
+ 16 April 2019

### Other references

* <http://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html>
* <https://www.cve.org/CVERecord?id=CVE-2019-2422>
