Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jython | Jul 30, 2024 | Feb 13, 2015 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 25869659 for version 12.1.3.0.0.Apply the Patch Set Update (PSU) 25961827 for version 12.2.1.1.0.Apply the Patch Set Update (PSU) 25869650 for version 10.3.6.0.0.Apply the Patch Set Update (PSU) 25871788 for version 12.2.1.2.0. | Apr 3, 2018 | Feb 13, 2015 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Apr 3, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 3, 2013 |
| Suse | — | Upgrade jython-demoUpgrade jython-manualUpgrade jythonUpgrade jython-javadoc | Feb 23, 2015 | Feb 13, 2015 |
| Ubuntu | — | Upgrade jython | Nov 19, 2024 | Feb 13, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub