CVE-2008-0628

Advisory lineage Upstream: 0 Downstream: 1
Downstream
Modified
Published: 06 Feb 2008, 20:00
Last modified:07 Aug 2024, 07:54

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
7.8 HIGH
v2.0 (nvd)
EPSS Score
6.78% LOW
7% probability +0.77%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Feb 2008, 20:00
Published
Vulnerability first disclosed
07 Aug 2024, 07:54
Last Modified
Vulnerability information updated

Description

The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the "external general entities" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.

CVSS Metrics

  • v2.0HIGHScore: 7.8AV:N/AC:M/Au:N/C:N/I:P/A:C

EPSS Trends

Current EPSS score: 6.78% Percentile: 91%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • sunjdk

    1.6

  • sunjre

    ≤ 1.6.0

References (18)