Lucene search

K
cve[email protected]CVE-2009-1106
HistoryMar 25, 2009 - 11:30 p.m.

CVE-2009-1106

2009-03-2523:30:00
CWE-20
web.nvd.nist.gov
59
java
plug-in
jdk
jre
cve-2009-1106
security
nvd

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

7.3 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

81.0%

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.

Affected configurations

NVD
Node
sunjdkMatch1.6.0update_10
OR
sunjdkMatch1.6.0update_11
OR
sunjdkMatch1.6.0update_12
OR
sunjreMatch1.6.0update_10
OR
sunjreMatch1.6.0update_11
OR
sunjreMatch1.6.0update_12
CPENameOperatorVersion
sun:jdksun jdkeq1.6.0
sun:jresun jreeq1.6.0

References

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

7.3 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

81.0%