CVE-2008-5347
Advisory lineage Upstream: 0 Downstream: 2
Downstream
Modified
Published: 05 Dec 2008, 11:00
Last modified:07 Aug 2024, 10:49
Vulnerability Summary
Overall Risk (default)
medium
31/100 CVSS Score
7.5 HIGH
v2.0 (nvd)
EPSS Score
2.77% LOW
3% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
05 Dec 2008, 11:00
Published
Vulnerability first disclosed
07 Aug 2024, 10:49
Last Modified
Vulnerability information updated
Description
Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applications to gain privileges via vectors related to access to inner classes in the (1) JAX-WS and (2) JAXB packages.
CVSS Metrics
- v2.0•HIGH•Score: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 2.77%• Percentile: 86%
Techniques & Countermeasures
- CWE-264•Permissions, Privileges, and Access Controls
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Affected Systems
- sun•jdk
≤ 6 | 6 | 6:update_1 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5 | 6:update_6 | 6:update_7 | 6:update_8
- sun•jre
≤ 6 | 6 | 6:update_1 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5 | 6:update_6 | 6:update_7 | 6:update_8
References (26)
- http://marc.info/?l=bugtraq&m=126583436323697&w=2
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-246366-1
- http://www.securitytracker.com/id?1021307
- http://secunia.com/advisories/34259
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47068
- http://www.vupen.com/english/advisories/2009/0672
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1019798.1-1
- http://rhn.redhat.com/errata/RHSA-2008-1018.html
- http://secunia.com/advisories/33015
- http://secunia.com/advisories/34233
- http://security.gentoo.org/glsa/glsa-200911-02.xml
- http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2009/03/024431-01.pdf
- http://osvdb.org/50506
- http://marc.info/?l=bugtraq&m=123678756409861&w=2
- http://secunia.com/advisories/38539
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html
- http://secunia.com/advisories/33528
- http://www.vupen.com/english/advisories/2008/3339
- http://www.us-cert.gov/cas/techalerts/TA08-340A.html
- http://secunia.com/advisories/33709
- http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=829914&poid=
- http://www.redhat.com/support/errata/RHSA-2009-0015.html
- http://secunia.com/advisories/32991
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5633
- http://www.securityfocus.com/bid/32608
- http://secunia.com/advisories/37386