CVE-2009-2670

Advisory lineage Upstream: 0 Downstream: 7
Modified
Published: 05 Aug 2009, 19:00
Last modified:07 Aug 2024, 05:59

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
3.65% LOW
4% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Aug 2009, 19:00
Published
Vulnerability first disclosed
07 Aug 2024, 05:59
Last Modified
Vulnerability information updated

Description

The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 3.65% Percentile: 88%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • sunjdk

    ≤ 6 | 5.0:update_1 | 5.0:update_10 | 5.0:update_11 | 5.0:update_12 | 5.0:update_13 | 5.0:update_14 | 5.0:update_15 | 5.0:update_16 | 5.0:update_17 | 5.0:update_2 | 5.0:update_3 | 5.0:update_4 | 5.0:update_5 | 5.0:update_6 | 5.0:update_7 | 5.0:update_8 | 5.0:update_9 | 6:update_1 | 6:update_10 | 6:update_11 | 6:update_12 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5 | 6:update_6 | 6:update_7 | 6:update_8 | 6:update_9

  • sunjre

    ≤ 6 | 5.0:update_1 | 5.0:update_10 | 5.0:update_11 | 5.0:update_12 | 5.0:update_13 | 5.0:update_14 | 5.0:update_15 | 5.0:update_16 | 5.0:update_17 | 5.0:update_19 | 5.0:update_2 | 5.0:update_3 | 5.0:update_4 | 5.0:update_5 | 5.0:update_6 | 5.0:update_7 | 5.0:update_8 | 5.0:update_9 | 6:update_1 | 6:update_10 | 6:update_11 | 6:update_12 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5 | 6:update_6 | 6:update_7 | 6:update_8 | 6:update_9

References (36)