CVE-2008-3112

Aliases:CGA-27x8-7pjx-6wgmCGA-32rp-j7w6-7hrqCGA-3rpg-6h37-2j52CGA-4c53-46gg-9rc7CGA-4wqv-2x3p-x5rwCGA-53q7-8xvv-fhq8CGA-56hr-c484-vmpmCGA-5gc9-r6c6-j3hqCGA-5rhp-r5c3-j89gCGA-6485-464v-59vpCGA-66hv-849x-43j9CGA-6jr8-4x2q-3ghmCGA-6v2w-vgpg-4rj4CGA-739m-7r7c-99wwCGA-778f-cjj5-639pCGA-782h-8vvf-744rCGA-7ghf-87jc-4v42CGA-7qgc-xq4h-cfhcCGA-822m-ffg5-2r89CGA-82mw-r8j7-3p38CGA-8rx2-m8rq-66vwCGA-8xgw-r64q-mx4pCGA-c2g3-wcw2-r98vCGA-c3c3-3p86-gp25CGA-c8pp-2r3r-p888CGA-cjjg-h6px-938jCGA-cmvh-j6j8-cj52CGA-cw33-4gc9-fhqmCGA-f395-98p6-p3w5CGA-f3c7-qvgg-xcr6CGA-f4xj-5p97-757rCGA-f88x-q8wx-xp6vCGA-fpf6-65w7-236vCGA-fx8w-jr44-vxmqCGA-g68f-cxwg-rg94CGA-g8m5-pmmj-7g39CGA-h9jg-77hh-43xvCGA-hcjg-fr69-qm8rCGA-hhj9-2r2g-q7wqCGA-j2gr-gj76-fpgxCGA-jh2x-r9fh-p7q8CGA-jp8p-pw7v-8mxrCGA-m5rq-ff56-cp37CGA-m63g-hcqr-j84cCGA-mj2r-f5mv-c542CGA-mjh2-65jx-p297CGA-p567-9mm9-w5wjCGA-p9v4-67j6-88hmCGA-pjf3-crc6-xfg4CGA-pr9m-xgcm-q29mCGA-pxg7-7jvc-wf5qCGA-pxx8-38wv-652qCGA-q273-3425-x3g3CGA-q8xw-rv2x-34vxCGA-qhx9-87q5-f4v5CGA-qjhw-32p4-9h65CGA-r28f-32wf-c5qrCGA-r4hh-6vgr-rh98CGA-rfmg-c358-8897CGA-rmxq-q87p-85hjCGA-v34j-x3wc-mpwfCGA-v5xf-v8x9-g3g2CGA-v9ff-cw93-q3r3CGA-vjv4-cwrr-cfvwCGA-vp34-pg79-m4jxCGA-vppg-rp7g-cm66CGA-vrmv-9fmp-mp8vCGA-vx28-mr67-vq34CGA-w37f-83h7-wq68CGA-w54g-rqm7-vmm6CGA-w8v5-8p5w-63jcCGA-w9p6-f6wp-4c82CGA-wmhf-w963-x6h9CGA-ww7c-2mrx-c2rvCGA-xhjw-4f89-872vCGA-xpf8-3p46-3xggCGA-xr3v-rfpx-f73cCGA-xwx3-f546-vg2v
Advisory lineage Upstream: 0 Downstream: 7
Modified
Published: 09 Jul 2008, 23:00
Last modified:07 Aug 2024, 09:28

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
10 HIGH
v2.0 (nvd)
EPSS Score
25.73% HIGH
26% probability +17.35%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jul 2008, 23:00
Published
Vulnerability first disclosed
07 Aug 2024, 09:28
Last Modified
Vulnerability information updated

Description

Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create arbitrary files via the writeManifest method in the CacheEntry class, aka CR 6703909.

CVSS Metrics

  • v2.0HIGHScore: 10AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 25.73% Percentile: 98%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • chainguardopenjdk-11-openj9

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-dbg

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-default-jdk

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-default-jvm

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-doc

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-jmods

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-jre

    < 0.59.0-r2

  • chainguardopenjdk-17-openj9

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-doc

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-doc

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-doc

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-jre

    < 0.59.0-r1

  • sunjdk

    ≤ 5.0 | ≤ 6 | 5.0:update_10 | 5.0:update_11 | 5.0:update_12 | 5.0:update_13 | 5.0:update_14 | 5.0:update_2 | 5.0:update_3 | 5.0:update_4 | 5.0:update_5 | 5.0:update_6 | 5.0:update_7 | 5.0:update_8 | 5.0:update_9 | 6:update_1 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5

  • sunjre

    ≤ 1.4.2_17 | ≤ 5.0 | ≤ 6 | 1.4.2 | 1.4.2_01 | 1.4.2_02 | 1.4.2_03 | 1.4.2_04 | 1.4.2_05 | 1.4.2_06 | 1.4.2_07 | 1.4.2_8 | 1.4.2_9 | 1.4.2_10 | 1.4.2_11 | 1.4.2_12 | 1.4.2_13 | 1.4.2_14 | 1.4.2_15 | 1.4.2_16 | 5.0:update_1 | 5.0:update_10 | 5.0:update_11 | 5.0:update_12 | 5.0:update_13 | 5.0:update_14 | 5.0:update_2 | 5.0:update_3 | 5.0:update_4 | 5.0:update_5 | 5.0:update_6 | 5.0:update_7 | 5.0:update_8 | 5.0:update_9 | 6:update_1 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5

  • sunsdk

    1.4.2 | 1.4.2_01 | 1.4.2_02 | 1.4.2_03 | 1.4.2_04 | 1.4.2_05 | 1.4.2_06 | 1.4.2_07 | 1.4.2_08 | 1.4.2_09 | 1.4.2_10 | 1.4.2_11 | 1.4.2_12 | 1.4.2_13 | 1.4.2_14 | 1.4.2_15 | 1.4.2_16 | 1.4.2_17

References (41)