CVE-2019-2981: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are
lowvulnerability
security
Summary
CVE-2019-2981 is a vulnerability in Oracle's JAXP component (a Java library for processing XML data) that affects multiple versions of Java SE and Java SE Embedded. An attacker with network access can exploit this vulnerability to cause a partial denial of service (temporary disruption of service), particularly in Java applications that run untrusted code from the internet.
Vulnerability Details
CVSS Score
3.7(low)
EPSS (30-day exploit probability)
EPSS: 0.5%
Classification
Attack SophisticationModerate
Original source: https://nvd.nist.gov/vuln/detail/CVE-2019-2981
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%