Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, on Windows does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read local files via an untrusted application.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Hpux | — | Update Jre14.JRE14-PA20 to the latest versionUpdate Jdk15.JDK15-PA20W to the latest versionUpdate Jpi14.JPI14-COM-DOC to the latest versionUpdate Jdk14.JDK14-PA20 to the latest versionUpdate Jdk15.JDK15-COM to the latest versionUpdate Jdk14.JDK14-PWV2 to the latest versionUpdate Jre14.JRE14-PA20-HS to the latest versionUpdate Jpi14.JPI14-COM to the latest versionUpdate Jre14.JRE14-IPF32 to the latest versionUpdate Jre14.JRE14-IPF64 to the latest versionUpdate Jdk15.JDK15-PA20 to the latest versionUpdate Jre15.JRE15-PA20W-HS to the latest versionUpdate Jre14.JRE14-PWV2-H to the latest versionUpdate Jre15.JRE15-PNV2-H to the latest versionUpdate Jre14.JRE14-PWV2 to the latest versionUpdate Jdk14.JDK14-IPF32 to the latest versionUpdate Jre14.JRE14-PA20W-HS to the latest versionUpdate Jre14.JRE14-IPF64-HS to the latest versionUpdate Jdk15.JDK15-PNV2 to the latest versionUpdate Jre15.JRE15-IPF32 to the latest versionUpdate Jre14.JRE14-IPF32-HS to the latest versionUpdate Jre15.JRE15-PNV2 to the latest versionUpdate Jre14.JRE14-PA11-HS to the latest versionUpdate Jre15.JRE15-IPF32-HS to the latest versionUpdate Jdk14.JDK14-IPF64 to the latest versionUpdate Jdk15.JDK15-IPF32 to the latest versionUpdate Jdk15.JDK15-PWV2 to the latest versionUpdate Jdk14.JDK14-PA20W to the latest versionUpdate Jre15.JRE15-COM to the latest versionUpdate Jre14.JRE14-PNV2 to the latest versionUpdate Jdk15.JDK15-DEMO to the latest versionUpdate Jre15.JRE15-PA20W to the latest versionUpdate Jpi14.JPI14-IPF32 to the latest versionUpdate Jre15.JRE15-PA20 to the latest versionUpdate Jdk14.JDK14-DEMO to the latest versionUpdate Jre15.JRE15-PWV2-H to the latest versionUpdate Jre14.JRE14-COM to the latest versionUpdate Jpi14.JPI14-PA11 to the latest versionUpdate Jre15.JRE15-COM-DOC to the latest versionUpdate Jdk14.JDK14-PNV2 to the latest versionUpdate Jre14.JRE14-PA11 to the latest versionUpdate Jre15.JRE15-PA20-HS to the latest versionUpdate Jre14.JRE14-PA20W to the latest versionUpdate Jre14.JRE14-COM-DOC to the latest versionUpdate Jre15.JRE15-IPF64 to the latest versionUpdate Jre15.JRE15-IPF64-HS to the latest versionUpdate Jre14.JRE14-PNV2-H to the latest versionUpdate Jdk15.JDK15-IPF64 to the latest versionUpdate Jdk14.JDK14-PA11 to the latest versionUpdate Jre15.JRE15-PWV2 to the latest versionUpdate Jdk14.JDK14-COM to the latest version | Aug 11, 2017 | Oct 5, 2007 |
| Suse | — | Upgrade java-1_4_2-ibm-jdbcUpgrade java-1_4_2-ibmUpgrade java-1_4_2-ibm-plugin | Feb 17, 2015 | Jul 9, 2013 |
| Vmsa 2008 0010 | — | Apply ESX350-200806404-SG. | Nov 19, 2010 | Oct 6, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub