cbcvebase.
CVE-2007-3504
published 2007-06-30

CVE-2007-3504: Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE…

PriorityP345critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.42%
92.9th percentile
Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execute arbitrary code by overwriting a .java.policy file.

Affected

4 ranges
VendorProductVersion rangeFixed in
sunjdk<= 1.5.0
sunjre<= 1.4.2
sunjre<= 1.5.0
sunsdk<= 1.4.2_13
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.