Lucene search

K
cveRedhatCVE-2009-3881
HistoryNov 09, 2009 - 7:30 p.m.

CVE-2009-3881

2009-11-0919:30:00
CWE-200
redhat
web.nvd.nist.gov
66
cve-2009-3881
sun java se
update 22
update 17
openjdk
classloader
remote attack
information leak
bug id 6636650

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.019

Percentile

88.5%

Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain privileges via unspecified vectors, related to an “information leak vulnerability,” aka Bug Id 6636650.

Affected configurations

Nvd
Node
sunjreRange1.5.0update_21
OR
sunjreRange1.6.0update_16
OR
sunjreMatch1.5.0update_1
OR
sunjreMatch1.5.0update_11
OR
sunjreMatch1.5.0update_12
OR
sunjreMatch1.5.0update_13
OR
sunjreMatch1.5.0update_14
OR
sunjreMatch1.5.0update_15
OR
sunjreMatch1.5.0update_16
OR
sunjreMatch1.5.0update_17
OR
sunjreMatch1.5.0update_18
OR
sunjreMatch1.5.0update_19
OR
sunjreMatch1.5.0update_2
OR
sunjreMatch1.5.0update_20
OR
sunjreMatch1.5.0update_3
OR
sunjreMatch1.5.0update_4
OR
sunjreMatch1.5.0update_5
OR
sunjreMatch1.5.0update_6
OR
sunjreMatch1.5.0update_7
OR
sunjreMatch1.5.0update_8
OR
sunjreMatch1.5.0update_9
OR
sunjreMatch1.5.0update10
OR
sunjreMatch1.6.0update_1
OR
sunjreMatch1.6.0update_10
OR
sunjreMatch1.6.0update_11
OR
sunjreMatch1.6.0update_12
OR
sunjreMatch1.6.0update_13
OR
sunjreMatch1.6.0update_14
OR
sunjreMatch1.6.0update_15
OR
sunjreMatch1.6.0update_2
OR
sunjreMatch1.6.0update_3
OR
sunjreMatch1.6.0update_4
OR
sunjreMatch1.6.0update_5
OR
sunjreMatch1.6.0update_6
OR
sunjreMatch1.6.0update_7
OR
sunjreMatch1.6.0update_8
OR
sunjreMatch1.6.0update_9
OR
sunopenjdk
VendorProductVersionCPE
sunjre*cpe:2.3:a:sun:jre:*:update_21:*:*:*:*:*:*
sunjre*cpe:2.3:a:sun:jre:*:update_16:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_1:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_11:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_12:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_13:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_14:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_15:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_16:*:*:*:*:*:*
sunjre1.5.0cpe:2.3:a:sun:jre:1.5.0:update_17:*:*:*:*:*:*
Rows per page:
1-10 of 381

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.019

Percentile

88.5%