CVE-2019-2973: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are
lowvulnerability
security
Summary
CVE-2019-2973 is a vulnerability in Oracle Java SE's JAXP component (a tool for processing XML data) that affects versions 7u231, 8u221, 11.0.4, 13, and Java SE Embedded 8u221. An unauthenticated attacker with network access can exploit this flaw to cause a partial denial of service (temporary disruption where the system becomes partially unavailable), particularly in Java applications that run untrusted code from the internet.
Vulnerability Details
CVSS Score
3.7(low)
EPSS (30-day exploit probability)
EPSS: 0.4%
Classification
Attack SophisticationModerate
Original source: https://nvd.nist.gov/vuln/detail/CVE-2019-2973
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%