Unspecified vulnerability in the Oracle Communications Messaging Server (Sun Java System Messaging Server) component in Oracle Sun Products Suite 7.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Webmail. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that the Kerberos implementation does not properly check AP-REQ requests, which allows attackers to cause a denial of service in the JVM. NOTE: CVE has not investigated the apparent discrepancy between the two vendors regarding the consequences of this issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade java-1.6.0-openjdkUpgrade java-1.6.0-openjdk-javadocUpgrade java-1.6.0-openjdk-demoUpgrade java-1.6.0-openjdk-srcUpgrade java-1.6.0-openjdk-devel | Dec 1, 2016 | Oct 14, 2010 |
| Gentoo Linux | — | Upgrade dev-java/icedtea-bin. | Oct 30, 2017 | Oct 14, 2010 |
| Hpux | — | Update Jre60.JRE60-COM to the latest versionUpdate Jre60.JRE60-PA20-HS to the latest versionUpdate Jre60.JRE60-PA20 to the latest versionUpdate Jdk14.JDK14-IPF32 to the latest versionUpdate Jre14.JRE14-COM to the latest versionUpdate Jre15.JRE15-IPF64 to the latest versionUpdate Jdk15.JDK15-IPF32 to the latest versionUpdate Jdk15.JDK15-PA20 to the latest versionUpdate Jre60.JRE60-PA20W to the latest versionUpdate Jre15.JRE15-PA20W to the latest versionUpdate Jre15.JRE15-PA20W-HS to the latest versionUpdate Jdk60.JDK60-IPF32 to the latest versionUpdate Jre14.JRE14-IPF64 to the latest versionUpdate Jdk60.JDK60-IPF64 to the latest versionUpdate Jre14.JRE14-IPF64-HS to the latest versionUpdate Jre14.JRE14-PA20W-HS to the latest versionUpdate Jre14.JRE14-PA11-HS to the latest versionUpdate Jdk15.JDK15-COM to the latest versionUpdate Jdk14.JDK14-IPF64 to the latest versionUpdate Jre60.JRE60-IPF64-HS to the latest versionUpdate Jdk14.JDK14-PA20W to the latest versionUpdate Jre60.JRE60-IPF32-HS to the latest versionUpdate Jdk60.JDK60-COM to the latest versionUpdate Jre15.JRE15-IPF32 to the latest versionUpdate Jre14.JRE14-PA11 to the latest versionUpdate Jdk14.JDK14-PA11 to the latest versionUpdate Jre14.JRE14-PA20W to the latest versionUpdate Jre14.JRE14-PA20 to the latest versionUpdate Jre60.JRE60-IPF64 to the latest versionUpdate Jre60.JRE60-PA20W-HS to the latest versionUpdate Jdk14.JDK14-PA20 to the latest versionUpdate Jre14.JRE14-IPF32 to the latest versionUpdate Jdk15.JDK15-PA20W to the latest versionUpdate Jdk60.JDK60-PA20 to the latest versionUpdate Jre60.JRE60-IPF32 to the latest versionUpdate Jre15.JRE15-COM to the latest versionUpdate Jre14.JRE14-PA20-HS to the latest versionUpdate Jdk15.JDK15-IPF64 to the latest versionUpdate Jdk14.JDK14-COM to the latest versionUpdate Jre15.JRE15-IPF64-HS to the latest versionUpdate Jdk60.JDK60-PA20W to the latest versionUpdate Jre15.JRE15-PA20 to the latest versionUpdate Jre15.JRE15-PA20-HS to the latest versionUpdate Jre15.JRE15-IPF32-HS to the latest versionUpdate Jre14.JRE14-IPF32-HS to the latest version | Aug 11, 2017 | Oct 14, 2010 |
| Oracle_linux | — | Upgrade java-1.6.0-openjdk-srcUpgrade java-1.6.0-openjdk-develUpgrade java-1.6.0-openjdk-demoUpgrade java-1.6.0-openjdk-javadocUpgrade java-1.6.0-openjdk | Oct 16, 2024 | Oct 14, 2010 |
| Suse | — | Upgrade java-1_6_0-openjdkUpgrade java-1_6_0-openjdk-pluginUpgrade java-1_6_0-openjdk-demoUpgrade java-1_6_0-openjdk-develUpgrade java-1_6_0-openjdk-javadocUpgrade java-1_6_0-openjdk-src | Dec 12, 2013 | Oct 14, 2010 |
| Ubuntu | — | Upgrade openjdk-6-jdkUpgrade icedtea6-pluginUpgrade openjdk-6-jreUpgrade openjdk-6-jre-headless | Nov 8, 2024 | Oct 14, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub