Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-2689

Опубликовано: 05 авг. 2009
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=513222OpenJDK JDK13Services grants unnecessary privileges (6777448)

EPSS

Процентиль: 92%
0.07928
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.

nvd
около 16 лет назад

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.

debian
около 16 лет назад

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 b ...

github
больше 3 лет назад

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.

oracle-oval
около 16 лет назад

ELSA-2009-1201: java-1.6.0-openjdk security and bug fix update (IMPORTANT)

EPSS

Процентиль: 92%
0.07928
Низкий

5.8 Medium

CVSS2