CVE-2008-3114

Aliases:CGA-2j36-653c-4rxfCGA-2xrf-36cc-6jv5CGA-3fxm-jwr2-fh4qCGA-3p2w-vmjw-3hc7CGA-3wcx-r7qq-fgmhCGA-4583-mr23-xq4hCGA-4968-3rv9-5w9xCGA-4q68-2432-c9vcCGA-4wph-fhvq-p5mqCGA-5223-2x44-9gmwCGA-5jfp-h272-74q9CGA-665g-89vf-whq9CGA-66fp-wr7w-cgfmCGA-6924-g6qc-5fgcCGA-77vw-6g9g-c4vwCGA-799x-2458-whcpCGA-7cw6-p59m-r8jxCGA-7vvw-c6ph-2c52CGA-7x4j-2882-2jqjCGA-83j3-748j-8mhmCGA-86pq-38gx-wqffCGA-8hrr-fh75-3624CGA-8p9h-h9mj-35j5CGA-9582-cgp6-5gmfCGA-95cw-5w53-6jj8CGA-985h-3xxq-949hCGA-987g-9grr-2vqvCGA-9fmq-9gvv-gf3rCGA-9gvf-v3f9-cmfqCGA-cgxv-h693-4569CGA-cjwr-vrvr-gfm5CGA-cpvq-wmw6-f5vjCGA-cr7p-pwxc-vhhmCGA-cvjm-h2qf-w2v6CGA-cxjh-3w25-gq58CGA-f2vx-4xc3-rr3mCGA-f4rg-gr4r-mj7mCGA-f7vq-7mw7-p26mCGA-g8gm-m8wm-qjm2CGA-gprf-p4x9-8whpCGA-grv4-9xc7-g657CGA-h2jg-wg2r-5xm2CGA-h3rc-q2g5-g6pwCGA-h6x6-6gw5-fm98CGA-h9w4-hhqp-6c25CGA-hv54-9v44-c87vCGA-j69c-w655-fcfjCGA-j79p-36fg-4pv7CGA-j9rp-6wc8-7gv9CGA-jjw6-x946-52hrCGA-jvvp-5pjv-9xfqCGA-m2pg-3cc4-qxvjCGA-mcvf-g4p3-f6mgCGA-mg29-p79x-wwv9CGA-p4wf-22qv-5cxcCGA-pf9h-7fxh-mq7pCGA-pm88-crqh-xp43CGA-pm89-qm5x-3c6mCGA-pmwx-53rf-66qcCGA-pqcq-9j2c-jx9mCGA-pqxf-8g8x-7m9gCGA-px9x-f3cv-pv3gCGA-qf8h-rh6h-wjcfCGA-qwvw-hf82-7563CGA-rqxg-2hxr-qj4hCGA-rrjf-3q4r-7cwwCGA-rwqc-7799-599wCGA-v43h-vxp8-2xw4CGA-v98x-4r5m-739rCGA-vwgq-4r4c-9g4xCGA-w57m-hc23-j2xqCGA-wp62-fj49-227qCGA-x2vw-m8f9-5hhfCGA-x4rh-v45r-gg5fCGA-x76f-6j26-qjvxCGA-x96v-rphh-4c2cCGA-xpv6-rq94-r336CGA-xvx2-q3w2-h7xc
Advisory lineage Upstream: 0 Downstream: 7
Modified
Published: 09 Jul 2008, 23:00
Last modified:07 Aug 2024, 09:28

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
3.06% LOW
3% probability -0.27%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jul 2008, 23:00
Published
Vulnerability first disclosed
07 Aug 2024, 09:28
Last Modified
Vulnerability information updated

Description

Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to obtain sensitive information (the cache location) via an untrusted application, aka CR 6704074.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 3.06% Percentile: 87%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • chainguardopenjdk-11-openj9

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-dbg

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-default-jdk

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-default-jvm

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-doc

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-jmods

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-jre

    < 0.59.0-r2

  • chainguardopenjdk-17-openj9

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-doc

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-doc

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-doc

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-jre

    < 0.59.0-r1

  • sunjdk

    ≤ 5.0 | ≤ 6 | 5.0:update_10 | 5.0:update_11 | 5.0:update_12 | 5.0:update_13 | 5.0:update_14 | 5.0:update_2 | 5.0:update_3 | 5.0:update_4 | 5.0:update_5 | 5.0:update_6 | 5.0:update_7 | 5.0:update_8 | 5.0:update_9 | 6:update_1 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5

  • sunjre

    ≤ 1.4.2_17 | ≤ 5.0 | ≤ 6 | 1.4.2 | 1.4.2_01 | 1.4.2_02 | 1.4.2_03 | 1.4.2_04 | 1.4.2_05 | 1.4.2_06 | 1.4.2_07 | 1.4.2_8 | 1.4.2_9 | 1.4.2_10 | 1.4.2_11 | 1.4.2_12 | 1.4.2_13 | 1.4.2_14 | 1.4.2_15 | 1.4.2_16 | 5.0:update_1 | 5.0:update_10 | 5.0:update_11 | 5.0:update_12 | 5.0:update_13 | 5.0:update_14 | 5.0:update_2 | 5.0:update_3 | 5.0:update_4 | 5.0:update_5 | 5.0:update_6 | 5.0:update_7 | 5.0:update_8 | 5.0:update_9 | 6:update_1 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5

  • sunsdk

    ≤ 1.4.2_17 | 1.4.2 | 1.4.2_01 | 1.4.2_02 | 1.4.2_03 | 1.4.2_04 | 1.4.2_05 | 1.4.2_06 | 1.4.2_07 | 1.4.2_08 | 1.4.2_09 | 1.4.2_10 | 1.4.2_11 | 1.4.2_12 | 1.4.2_13 | 1.4.2_14 | 1.4.2_15 | 1.4.2_16

References (40)