Lucene search

K
nvd[email protected]NVD:CVE-2009-3865
HistoryNov 05, 2009 - 4:30 p.m.

CVE-2009-3865

2009-11-0516:30:00
CWE-94
web.nvd.nist.gov
1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.011 Low

EPSS

Percentile

84.2%

The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.

Affected configurations

NVD
Node
sunjdkMatch1.6.0update1
OR
sunjdkMatch1.6.0update1_b06
OR
sunjdkMatch1.6.0update10
OR
sunjdkMatch1.6.0update11
OR
sunjdkMatch1.6.0update12
OR
sunjdkMatch1.6.0update13
OR
sunjdkMatch1.6.0update14
OR
sunjdkMatch1.6.0update15
OR
sunjdkMatch1.6.0update16
OR
sunjdkMatch1.6.0update2
OR
sunjdkMatch1.6.0update3
OR
sunjdkMatch1.6.0update4
OR
sunjdkMatch1.6.0update5
OR
sunjdkMatch1.6.0update6
OR
sunjdkMatch1.6.0update7
OR
sunjdkMatch1.6.0update8
OR
sunjdkMatch1.6.0update9
OR
sunjreMatch1.6.0update_1
OR
sunjreMatch1.6.0update_2
OR
sunjreMatch1.6.0update_3
OR
sunjreMatch1.6.0update10
OR
sunjreMatch1.6.0update11
OR
sunjreMatch1.6.0update12
OR
sunjreMatch1.6.0update13
OR
sunjreMatch1.6.0update14
OR
sunjreMatch1.6.0update15
OR
sunjreMatch1.6.0update16
OR
sunjreMatch1.6.0update4
OR
sunjreMatch1.6.0update5
OR
sunjreMatch1.6.0update6
OR
sunjreMatch1.6.0update7
OR
sunjreMatch1.6.0update8
OR
sunjreMatch1.6.0update9

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.011 Low

EPSS

Percentile

84.2%