CVE-2007-2435

CWE-2644 documents4 sources
Severity
10.0CRITICAL
EPSS
3.7%
top 12.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 1

Description

Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, allows remote attackers to perform unauthorized actions via an application that grants privileges to itself, related to "Incorrect Use of System Classes" and probably related to support for JNLP files.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

NVDsun/jre1.4.2+1
NVDsun/sdk1.4.3_13

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9ffv-4whq-h9qg: Sun Java Web Start in JDK and JRE 52022-05-01
CVEList
CVE-2007-2435: Sun Java Web Start in JDK and JRE 52007-05-02

📋Vendor Advisories

1
Red Hat
javaws vulnerabilities2007-04-30
CVE-2007-2435 (CRITICAL CVSS 10) | Sun Java Web Start in JDK and JRE 5 | cvebase.io