High severity8.2NVD Advisory· Published Jul 31, 2019· Updated Jun 17, 2026
CVE-2019-10182
CVE-2019-10182
Description
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16cpe:2.3:a:icedtea-web_project:icedtea-web:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:icedtea-web_project:icedtea-web:*:*:*:*:*:*:*:*range: <=1.7.2
- cpe:2.3:a:icedtea-web_project:icedtea-web:1.8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
- Range: <=1.7.2, <=1.8.2
- osv-coords7 versionspkg:rpm/opensuse/icedtea-web&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/icedtea-web&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/icedtea-web&distro=openSUSE%20Tumbleweedpkg:rpm/suse/icedtea-web&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/icedtea-web&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4pkg:rpm/suse/icedtea-web&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/icedtea-web&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3
< 1.7.2-lp150.2.3.1+ 6 more
- (no CPE)range: < 1.7.2-lp150.2.3.1
- (no CPE)range: < 1.7.2-150100.7.3.1
- (no CPE)range: < 1.8.6-1.3
- (no CPE)range: < 1.7.2-150100.7.3.1
- (no CPE)range: < 1.7.2-150100.7.3.1
- (no CPE)range: < 1.7.2-3.3.1
- (no CPE)range: < 1.7.2-150100.7.3.1
- IcedTea/icedtea-webv5Range: affects up to and including 1.7.2 and 1.8.2
Patches
Vulnerability mechanics
References
7- github.com/AdoptOpenJDK/IcedTea-Web/issues/327nvdPatchThird Party Advisory
- github.com/AdoptOpenJDK/IcedTea-Web/pull/344nvdPatchThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-08/msg00045.htmlnvd
- packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.htmlnvd
- lists.debian.org/debian-lts-announce/2019/09/msg00008.htmlnvd
- seclists.org/bugtraq/2019/Oct/5nvd
News mentions
0No linked articles in our index yet.