Lucene search

K
cve[email protected]CVE-2009-3884
HistoryNov 09, 2009 - 7:30 p.m.

CVE-2009-3884

2009-11-0919:30:00
web.nvd.nist.gov
74
cve-2009-3884
sun java
remote attack
file disclosure
bug id 6824265

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.8 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.9%

The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.

Affected configurations

NVD
Node
sunjreRange1.5.0update_21
OR
sunjreRange1.6.0update_16
OR
sunjreMatch1.5.0update_1
OR
sunjreMatch1.5.0update_11
OR
sunjreMatch1.5.0update_12
OR
sunjreMatch1.5.0update_13
OR
sunjreMatch1.5.0update_14
OR
sunjreMatch1.5.0update_15
OR
sunjreMatch1.5.0update_16
OR
sunjreMatch1.5.0update_17
OR
sunjreMatch1.5.0update_18
OR
sunjreMatch1.5.0update_19
OR
sunjreMatch1.5.0update_2
OR
sunjreMatch1.5.0update_20
OR
sunjreMatch1.5.0update_3
OR
sunjreMatch1.5.0update_4
OR
sunjreMatch1.5.0update_5
OR
sunjreMatch1.5.0update_6
OR
sunjreMatch1.5.0update_7
OR
sunjreMatch1.5.0update_8
OR
sunjreMatch1.5.0update_9
OR
sunjreMatch1.5.0update10
OR
sunjreMatch1.6.0update_1
OR
sunjreMatch1.6.0update_10
OR
sunjreMatch1.6.0update_11
OR
sunjreMatch1.6.0update_12
OR
sunjreMatch1.6.0update_13
OR
sunjreMatch1.6.0update_14
OR
sunjreMatch1.6.0update_15
OR
sunjreMatch1.6.0update_2
OR
sunjreMatch1.6.0update_3
OR
sunjreMatch1.6.0update_4
OR
sunjreMatch1.6.0update_5
OR
sunjreMatch1.6.0update_6
OR
sunjreMatch1.6.0update_7
OR
sunjreMatch1.6.0update_8
OR
sunjreMatch1.6.0update_9
OR
sunopenjdk

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.8 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.9%