CVE-2009-2673

Aliases:CGA-28x4-gwgv-fxfxCGA-2cp9-4x87-c6rfCGA-2q5c-w5jf-h42rCGA-362j-ppjx-55cvCGA-3grw-4cgq-383xCGA-3xf2-gh9v-wqh4CGA-4wr6-w657-p56rCGA-4xxj-8c5x-3568CGA-57c5-hv7m-pmvwCGA-5hhm-r7wg-f3mvCGA-633c-65r4-5hf9CGA-67mg-ppwh-mfv4CGA-69w9-hfq2-gg4jCGA-6v76-rrvg-w4h8CGA-73m4-4x7g-frjmCGA-7g88-rq8f-2p2mCGA-7xc3-vm8v-qqp7CGA-82cf-5h92-56p4CGA-82cv-f4g4-w5rvCGA-8584-83r8-hfh9CGA-866w-c8ch-g8g5CGA-8fj5-jgvq-w2mwCGA-8hq2-g6f5-6r78CGA-8rc6-wmx2-pvrvCGA-928g-gqx9-243hCGA-95wg-pcc4-g934CGA-9chq-q966-5xpwCGA-9frc-4rv8-hx7xCGA-9gm9-rw3r-p8gwCGA-9vfr-q6m4-x3vmCGA-c2x2-8m59-qr3rCGA-c7r5-5mff-q7f9CGA-cc37-h73m-rjv5CGA-cw59-cv2v-w4wgCGA-ffw2-qr7m-h6prCGA-fg66-vfjc-9wcrCGA-fqc4-qvvq-j2p2CGA-g3g4-c39q-hv67CGA-g933-5w22-2f52CGA-ghwf-mv83-8mh7CGA-gjhw-3hr2-fpcwCGA-gpc6-29w3-6wcqCGA-gpr5-2cpj-6wc4CGA-gr73-9g45-m7xcCGA-h75c-wvmm-472fCGA-h833-h56c-r45fCGA-hvqh-f2pq-wjv4CGA-j76m-4gc5-qq2qCGA-j784-wm5g-7wpcCGA-j7m3-cww5-gxp8CGA-j822-9cp6-8pmqCGA-jcm9-4vr4-mhxqCGA-jmgc-7vqx-gq5xCGA-jmxj-w6rj-8wggCGA-jpx5-8xv5-4f8vCGA-m58p-3924-xwvhCGA-m7cf-hh5g-wh44CGA-mm9m-ffxc-6f6gCGA-mwxh-mxf5-3phwCGA-mx7c-f2rp-6rp5CGA-p43c-hgfm-gxhcCGA-pf89-pm4p-26ggCGA-pjvx-485c-mfjcCGA-pr6w-v73p-qj5vCGA-pxw5-xhjh-gh7rCGA-q24f-pghw-f545CGA-r32c-jwp4-hrpjCGA-r4hf-59g2-x7j9CGA-rwwq-7329-p276CGA-vfgj-ph6x-5crmCGA-vm9r-834v-8767CGA-vmgr-5c84-qvf4CGA-vr2x-7x8c-jhcmCGA-wmxf-6p57-whw7CGA-ww7c-9jc7-gjmgCGA-x8cc-w95v-2mqjCGA-xjrg-63vf-rx9wCGA-xq27-jhwm-2c63
Advisory lineage Upstream: 0 Downstream: 7
Modified
Published: 05 Aug 2009, 19:00
Last modified:07 Aug 2024, 05:59

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.5 HIGH
v2.0 (nvd)
EPSS Score
4.84% LOW
5% probability -6.55%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Aug 2009, 19:00
Published
Vulnerability first disclosed
07 Aug 2024, 05:59
Last Modified
Vulnerability information updated

Description

The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.

CVSS Metrics

  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 4.84% Percentile: 92%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • chainguardopenjdk-11-openj9

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-dbg

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-default-jdk

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-default-jvm

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-doc

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-jmods

    < 0.59.0-r2

  • chainguardopenjdk-11-openj9-jre

    < 0.59.0-r2

  • chainguardopenjdk-17-openj9

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-doc

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-17-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-doc

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-21-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-25-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jmods

    < 0.59.0-r1

  • chainguardopenjdk-26-openj9-jre

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-dbg

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-default-jdk

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-default-jvm

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-doc

    < 0.59.0-r1

  • chainguardopenjdk-8-openj9-jre

    < 0.59.0-r1

  • sunjdk

    ≤ 6 | 5.0:update_1 | 5.0:update_10 | 5.0:update_11 | 5.0:update_12 | 5.0:update_13 | 5.0:update_14 | 5.0:update_15 | 5.0:update_16 | 5.0:update_17 | 5.0:update_2 | 5.0:update_3 | 5.0:update_4 | 5.0:update_5 | 5.0:update_6 | 5.0:update_7 | 5.0:update_8 | 5.0:update_9 | 6:update_1 | 6:update_10 | 6:update_11 | 6:update_12 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5 | 6:update_6 | 6:update_7 | 6:update_8 | 6:update_9

  • sunjre

    ≤ 6 | 5.0:update_1 | 5.0:update_10 | 5.0:update_11 | 5.0:update_12 | 5.0:update_13 | 5.0:update_14 | 5.0:update_15 | 5.0:update_16 | 5.0:update_17 | 5.0:update_19 | 5.0:update_2 | 5.0:update_3 | 5.0:update_4 | 5.0:update_5 | 5.0:update_6 | 5.0:update_7 | 5.0:update_8 | 5.0:update_9 | 6:update_1 | 6:update_10 | 6:update_11 | 6:update_12 | 6:update_2 | 6:update_3 | 6:update_4 | 6:update_5 | 6:update_6 | 6:update_7 | 6:update_8 | 6:update_9

References (36)