Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-3504

Опубликовано: 30 июн. 2007
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execute arbitrary code by overwriting a .java.policy file.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:sun:jdk:*:update11:*:*:*:*:*:*
Версия до 1.5.0 (включая)
cpe:2.3:a:sun:jre:*:update13:*:*:*:*:*:*
Версия до 1.4.2 (включая)
cpe:2.3:a:sun:jre:*:update11:*:*:*:*:*:*
Версия до 1.5.0 (включая)
cpe:2.3:a:sun:sdk:*:*:*:*:*:*:*:*
Версия до 1.4.2_13 (включая)

EPSS

Процентиль: 90%
0.05158
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-22

Связанные уязвимости

ubuntu
почти 19 лет назад

Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execute arbitrary code by overwriting a .java.policy file.

debian
почти 19 лет назад

Directory traversal vulnerability in the PersistenceService in Sun Jav ...

github
почти 4 года назад

Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execute arbitrary code by overwriting a .java.policy file.

EPSS

Процентиль: 90%
0.05158
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-22