Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08 and earlier, and JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary application via unknown attack vectors, a different vulnerability than CVE-2005-3906. NOTE: this is associated with the "first issue" identified in SUNALERT:102003.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-java/sun-jdk.Upgrade dev-java/sun-jre-bin.Upgrade dev-java/blackdown-jdk.Upgrade dev-java/blackdown-jre. | Oct 30, 2017 | Nov 30, 2005 |
| Suse | — | Upgrade IBMJava2-SDKUpgrade IBMJava2-JREUpgrade java2-jreUpgrade java2 | Feb 17, 2015 | Nov 30, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub