Lucene search

K
cveRedhatCVE-2010-3860
HistoryDec 08, 2010 - 8:00 p.m.

CVE-2010-3860

2010-12-0820:00:01
CWE-200
redhat
web.nvd.nist.gov
32
icedtea
openjdk
cve-2010-3860
security
vulnerability

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

8.6

Confidence

High

EPSS

0.007

Percentile

80.5%

IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to obtain sensitive information including (1) user.name, (2) user.home, and (3) java.home system properties, and other sensitive information such as installation directories.

Affected configurations

Nvd
Node
redhaticedteaRange1.9.1
OR
redhaticedteaMatch1.5rc1
OR
redhaticedteaMatch1.5rc2
OR
redhaticedteaMatch1.5rc3
OR
redhaticedteaMatch1.6
OR
redhaticedteaMatch1.7
OR
redhaticedteaMatch1.8
OR
redhaticedteaMatch1.8.1
OR
redhaticedteaMatch1.8.2
OR
redhaticedteaMatch1.9
VendorProductVersionCPE
redhaticedtea*cpe:2.3:a:redhat:icedtea:*:*:*:*:*:*:*:*
redhaticedtea1.5cpe:2.3:a:redhat:icedtea:1.5:rc1:*:*:*:*:*:*
redhaticedtea1.5cpe:2.3:a:redhat:icedtea:1.5:rc2:*:*:*:*:*:*
redhaticedtea1.5cpe:2.3:a:redhat:icedtea:1.5:rc3:*:*:*:*:*:*
redhaticedtea1.6cpe:2.3:a:redhat:icedtea:1.6:*:*:*:*:*:*:*
redhaticedtea1.7cpe:2.3:a:redhat:icedtea:1.7:*:*:*:*:*:*:*
redhaticedtea1.8cpe:2.3:a:redhat:icedtea:1.8:*:*:*:*:*:*:*
redhaticedtea1.8.1cpe:2.3:a:redhat:icedtea:1.8.1:*:*:*:*:*:*:*
redhaticedtea1.8.2cpe:2.3:a:redhat:icedtea:1.8.2:*:*:*:*:*:*:*
redhaticedtea1.9cpe:2.3:a:redhat:icedtea:1.9:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

8.6

Confidence

High

EPSS

0.007

Percentile

80.5%