CVE-2007-3504Path Traversal in JDK

CWE-22Path Traversal3 documents3 sources
Severity
9.3CRITICALNVD
EPSS
5.2%
top 10.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 30
Latest updateMay 1

Description

Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execute arbitrary code by overwriting a .java.policy file.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

NVDsun/jdk1.5.0
NVDsun/jre1.4.2+1
NVDsun/sdk1.4.2_13

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vp9h-w4rm-xp28: Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 52022-05-01
CVEList
CVE-2007-3504: Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 52007-06-30
CVE-2007-3504 — Path Traversal in SUN JDK | cvebase