Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-3504

Опубликовано: 30 июн. 2007
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execute arbitrary code by overwriting a .java.policy file.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:sun:jdk:*:update11:*:*:*:*:*:*
Версия до 1.5.0 (включая)
cpe:2.3:a:sun:jre:*:update13:*:*:*:*:*:*
Версия до 1.4.2 (включая)
cpe:2.3:a:sun:jre:*:update11:*:*:*:*:*:*
Версия до 1.5.0 (включая)
cpe:2.3:a:sun:sdk:*:*:*:*:*:*:*:*
Версия до 1.4.2_13 (включая)

EPSS

Процентиль: 90%
0.05226
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-22

Связанные уязвимости

ubuntu
больше 18 лет назад

Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execute arbitrary code by overwriting a .java.policy file.

debian
больше 18 лет назад

Directory traversal vulnerability in the PersistenceService in Sun Jav ...

github
больше 3 лет назад

Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execute arbitrary code by overwriting a .java.policy file.

EPSS

Процентиль: 90%
0.05226
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-22