Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-2689

Опубликовано: 10 авг. 2009
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sun:java_se:*:20:*:*:*:*:*:*
Версия до 5.0 (включая)
cpe:2.3:a:sun:java_se:*:14:*:*:*:*:*:*
Версия до 6 (включая)
cpe:2.3:a:sun:openjdk:*:*:*:*:*:*:*:*

EPSS

Процентиль: 92%
0.07928
Низкий

10 Critical

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
около 16 лет назад

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.

redhat
около 16 лет назад

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.

debian
около 16 лет назад

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 b ...

github
больше 3 лет назад

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.

oracle-oval
около 16 лет назад

ELSA-2009-1201: java-1.6.0-openjdk security and bug fix update (IMPORTANT)

EPSS

Процентиль: 92%
0.07928
Низкий

10 Critical

CVSS2

Дефекты

CWE-264