CVE-2008-3105

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 09 Jul 2008, 23:00
Last modified:07 Aug 2024, 09:28

Vulnerability Summary

Overall Risk (default)
medium
38/100
CVSS Score
8.3 HIGH
v2.0 (nvd)
EPSS Score
22.46% HIGH
22% probability -2.56%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jul 2008, 23:00
Published
Vulnerability first disclosed
07 Aug 2024, 09:28
Last Modified
Vulnerability information updated

Description

Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to access URLs or cause a denial of service via unknown vectors involving "processing of XML data" by a trusted application.

CVSS Metrics

  • v2.0HIGHScore: 8.3AV:N/AC:M/Au:N/C:P/I:P/A:C

EPSS Trends

Current EPSS score: 22.46% Percentile: 96%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • sunjdk

    ≤ 6 | 6:update_1 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5

  • sunjre

    ≤ 6 | 6:update_1 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5

References (35)