Multiple unspecified vulnerabilities in reflection APIs in Java SDK and JRE 1.4.2_08 and earlier and JDK and JRE 5.0 Update 3 and earlier allow remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors, a different set of vulnerabilities than CVE-2005-3905. NOTE: this is associated with the "second and third issues" identified in SUNALERT:102003.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-java/sun-jre-bin.Upgrade dev-java/blackdown-jdk.Upgrade dev-java/sun-jdk.Upgrade dev-java/blackdown-jre. | Oct 30, 2017 | Nov 30, 2005 |
| Suse | — | Upgrade IBMJava2-JREUpgrade IBMJava2-SDKUpgrade java2Upgrade java2-jre | Feb 17, 2015 | Nov 30, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub