CVE-2008-2086

Aliases:CGA-237v-6fg9-8m67CGA-29r3-w35v-4g8rCGA-2f49-45hq-q746CGA-2v4v-773q-6f2mCGA-2wr4-6xjc-9fmfCGA-335j-w99q-2cxjCGA-3gcq-39ch-v67jCGA-3h35-g4xq-w42xCGA-3mjw-hhmq-mmx9CGA-3p5w-778m-xf87CGA-3x87-c8m8-7w9jCGA-465c-xh7h-vr98CGA-46pg-4mqc-3x5gCGA-49q7-gx8f-mw38CGA-4ww3-w32q-3jm8CGA-5gcx-rxvv-rr6hCGA-5rx2-3c5f-4r8gCGA-63f8-93gj-7f74CGA-645x-3jq9-w9m7CGA-677x-p392-6gc7CGA-6cwj-hmrv-h7rrCGA-6hj9-gv59-9347CGA-73f8-77cg-cfcfCGA-7f4w-4gcr-fw3gCGA-7j52-q75p-r2rqCGA-82h3-v9h5-rjm3CGA-86hm-x5vp-gj85CGA-885x-gx44-jj4pCGA-8h83-7x5g-gprmCGA-8jvm-wq2w-7q86CGA-92m4-hqc5-h6r4CGA-9458-8crx-p8x2CGA-984h-6jpw-v5hrCGA-9h24-67mv-m6qqCGA-9hm6-42h9-jw66CGA-c295-h4vx-w957CGA-c2ch-h5w2-f67hCGA-c893-qxvm-f77qCGA-cc84-7gj8-623pCGA-cg4v-qq49-q8h7CGA-cp25-vcw3-35x3CGA-f29w-4x48-5vvfCGA-fhmh-6wmg-75h5CGA-fm74-v6cc-vcj5CGA-fxhp-7g85-wgwvCGA-g4w6-2x3x-87cpCGA-gr22-qpc9-9hpvCGA-hf9w-x4x8-ghhhCGA-j59f-24q9-wr9fCGA-jhjq-wqh2-whxqCGA-jvv5-6fxr-r44gCGA-jxfw-99v9-q9pmCGA-m383-rgqw-r86jCGA-mf93-5pr9-vmj6CGA-mwf6-fgwj-752wCGA-p6cj-cvcj-www9CGA-pfm7-v42j-vq9wCGA-pqh5-68m8-vmm6CGA-q4f3-pxjq-wg3pCGA-qvx3-rphp-mc48CGA-qxf9-v5r7-h3f4CGA-r6hf-hpj8-w7vjCGA-rhvj-m9xp-4xr2CGA-rvgw-8px8-32pvCGA-v375-4vjh-mmwjCGA-vcpm-6x74-v98wCGA-vf9r-5cg3-5gwpCGA-vjm3-82p8-vffgCGA-w25v-qc3f-vr3jCGA-w5mf-j587-22w8CGA-w8gq-mrmh-f64mCGA-wcfq-328p-8xxrCGA-wv49-5fv7-8vcvCGA-wxgc-66xh-6v58CGA-x4cj-59wg-53hpCGA-x899-v67g-hmpcCGA-xf9m-q7xc-q9hhCGA-xgjq-vvgf-x2vw
Modified
Published: 05 Dec 2008, 02:00
Last modified:07 Aug 2024, 08:49

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.3 HIGH
v2.0 (nvd)
EPSS Score
7.32% LOW
7% probability -21.23%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Dec 2008, 02:00
Published
Vulnerability first disclosed
07 Aug 2024, 08:49
Last Modified
Vulnerability information updated

Description

Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3) user.home System Properties, aka "Java Web Start File Inclusion" and CR 6694892.

CVSS Metrics

  • v2.0HIGHScore: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 7.32% Percentile: 94%

Techniques & Countermeasures

  • CWE-94Improper Control of Generation of Code ('Code Injection')

    The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Affected Systems

  • chainguardopenjdk-11-openj9

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-dbg

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-default-jdk

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-default-jvm

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-doc

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-jmods

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-jre

    < 0.59.0-r2

  • chainguardopenjdk-17-openj9

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-doc

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-doc

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-doc

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-jre

    < 0.59.0-r1

  • sunjdk

    ≤ 5.0 | ≤ 6 | 5.0:update_1 | 5.0:update_10 | 5.0:update_11 | 5.0:update_12 | 5.0:update_13 | 5.0:update_14 | 5.0:update_15 | 5.0:update_2 | 5.0:update_3 | 5.0:update_4 | 5.0:update_5 | 5.0:update_6 | 5.0:update_7 | 5.0:update_8 | 5.0:update_9 | 6 | 6:update_1 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5 | 6:update_6 | 6:update_7 | 6:update_8 | 6:update_9

  • sunjre

    ≤ 1.4.2_18 | ≤ 5.0 | ≤ 6 | 1.4.2_1 | 1.4.2_2 | 1.4.2_3 | 1.4.2_4 | 1.4.2_5 | 1.4.2_6 | 1.4.2_7 | 1.4.2_8 | 1.4.2_9 | 1.4.2_10 | 1.4.2_11 | 1.4.2_12 | 1.4.2_13 | 1.4.2_14 | 1.4.2_15 | 1.4.2_16 | 1.4.2_17 | 5.0 | 5.0:update_1 | 5.0:update_10 | 5.0:update_11 | 5.0:update_12 | 5.0:update_13 | 5.0:update_14 | 5.0:update_15 | 5.0:update_2 | 5.0:update_3 | 5.0:update_4 | 5.0:update_5 | 5.0:update_6 | 5.0:update_7 | 5.0:update_8 | 5.0:update_9 | 6 | 6:update_1 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5 | 6:update_6 | 6:update_7 | 6:update_8 | 6:update_9

  • sunsdk

    ≤ 1.4.2_18 | 1.4.2_1 | 1.4.2_2 | 1.4.2_3 | 1.4.2_4 | 1.4.2_5 | 1.4.2_6 | 1.4.2_7 | 1.4.2_8 | 1.4.2_9 | 1.4.2_10 | 1.4.2_11 | 1.4.2_12 | 1.4.2_13 | 1.4.2_14 | 1.4.2_15 | 1.4.2_16 | 1.4.2_17

References (37)