It was discovered that the AccessController class implementation in the Security component of OpenJDK failed, in certain cases, to consider the current context and correctly restrict privileges based on it. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.
Public now via Oracle CPU July 2019: https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html#AppendixJAVA Fixed in Oracle Java SE 12.0.2, 11.0.4, and 8u221.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:1817 https://access.redhat.com/errata/RHSA-2019:1817
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:1810 https://access.redhat.com/errata/RHSA-2019:1810
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2019:1811 https://access.redhat.com/errata/RHSA-2019:1811
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:1815 https://access.redhat.com/errata/RHSA-2019:1815
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:1816 https://access.redhat.com/errata/RHSA-2019:1816
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2019:1840 https://access.redhat.com/errata/RHSA-2019:1840
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:1839 https://access.redhat.com/errata/RHSA-2019:1839
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-2786
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2019:2585 https://access.redhat.com/errata/RHSA-2019:2585
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:2590 https://access.redhat.com/errata/RHSA-2019:2590
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Supplementary Via RHSA-2019:2592 https://access.redhat.com/errata/RHSA-2019:2592
This issue has been addressed in the following products: Red Hat Satellite 5.8 Via RHSA-2019:2737 https://access.redhat.com/errata/RHSA-2019:2737
OpenJDK-11 upstream commit: http://hg.openjdk.java.net/jdk-updates/jdk11u/rev/190106d07f25 OpenJDK-8 upstream commit: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/dacc6a3dd712 OpenJDK-7 upstream commit: http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/708f34dd480f