Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-2476

Опубликовано: 10 авг. 2009
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sun:java_se:*:14:*:*:*:*:*:*
Версия до 6 (включая)
cpe:2.3:a:sun:openjdk:*:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.01825
Низкий

10 Critical

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
почти 16 лет назад

The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.

redhat
почти 16 лет назад

The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.

debian
почти 16 лет назад

The Java Management Extensions (JMX) implementation in Sun Java SE 6 b ...

github
около 3 лет назад

The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.

oracle-oval
почти 16 лет назад

ELSA-2009-1201: java-1.6.0-openjdk security and bug fix update (IMPORTANT)

EPSS

Процентиль: 82%
0.01825
Низкий

10 Critical

CVSS2

Дефекты

CWE-264