Lucene search

K
cve[email protected]CVE-2010-0840
HistoryApr 01, 2010 - 4:30 p.m.

CVE-2010-0840

2010-04-0116:30:00
web.nvd.nist.gov
853
In Wild
cve-2010-0840
information security
vulnerability
java
remote code execution
oracle

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0.948

Percentile

99.3%

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) “a similar trust issue with interfaces,” aka “Trusted Methods Chaining Remote Code Execution Vulnerability.”

Affected configurations

NVD
Node
oraclejreMatch1.4.2_25
OR
oraclejreMatch1.5.0update23
OR
oraclejreMatch1.6.0update18
Node
opensuseopensuseMatch11.0
OR
opensuseopensuseMatch11.1
OR
opensuseopensuseMatch11.2
Node
canonicalubuntu_linuxMatch8.04-
OR
canonicalubuntu_linuxMatch8.10
OR
canonicalubuntu_linuxMatch9.04
OR
canonicalubuntu_linuxMatch9.10
VendorProductVersionCPE
oraclejre1.6.0cpe:/a:oracle:jre:1.6.0:update18::
oraclejre1.5.0cpe:/a:oracle:jre:1.5.0:update23::
oraclejre1.4.2+25cpe:/a:oracle:jre:1.4.2+25:::

References

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0.948

Percentile

99.3%