Lucene search

K
cve[email protected]CVE-2002-0058
HistoryMar 15, 2002 - 5:00 a.m.

CVE-2002-0058

2002-03-1505:00:00
web.nvd.nist.gov
24
java runtime environment
jre vulnerability
session hijacking
java applet
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.6 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.4%

Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client’s sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 through 6.1 and 4.79 and earlier, (2) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, and possibly other implementations that use vulnerable versions of SDK or JDK.

Affected configurations

NVD
Node
microsoftvirtual_machineMatch3802
OR
sunjdkMatch1.1.8update13
OR
sunjdkMatch1.1.8update7
OR
sunjreMatch1.1.8update13
OR
sunjreMatch1.1.8update7
OR
sunjreMatch1.2.2update10
OR
sunjreMatch1.3.0update2
OR
sunsdkMatch1.1.8_007
OR
sunsdkMatch1.2.2_10
OR
sunsdkMatch1.2.2_010
OR
sunsdkMatch1.3_02

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.6 Medium

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.4%

Related for CVE-2002-0058