CVE-2007-5238
published 2007-10-06CVE-2007-5238: Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce…
PriorityP412low2.6CVSS 2.0
AVNACHAuNCPINAN
EPSS
2.66%
84.0th percentile
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka "three vulnerabilities."
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Vulnerabilities in Java Web Start allow to determine the location of the Java Web Start cache
vendor_redhat·2007-10-03·CVSS 2.6
CVE-2007-5238 [LOW] Vulnerabilities in Java Web Start allow to determine the location of the Java Web Start cache
Vulnerabilities in Java Web Start allow to determine the location of the Java Web Start cache
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka "three vulnerabilities."
GHSA
GHSA-p44h-q76r-8467: Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
ghsa_unreviewed·2022-05-01
CVE-2007-5238 [LOW] GHSA-p44h-q76r-8467: Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka "three vulnerabilities."
No detection rules found.
No public exploits indexed.
http://dev2dev.bea.com/pub/advisory/272http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlhttp://secunia.com/advisories/27206http://secunia.com/advisories/27261http://secunia.com/advisories/27693http://secunia.com/advisories/27716http://secunia.com/advisories/27804http://secunia.com/advisories/28777http://secunia.com/advisories/28880http://secunia.com/advisories/29042http://secunia.com/advisories/29858http://secunia.com/advisories/29897http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-103073-1http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.novell.com/linux/security/advisories/2007_55_java.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0963.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1041.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0132.htmlhttp://www.securityfocus.com/archive/1/482926/100/0/threadedhttp://www.securityfocus.com/bid/25920http://www.securitytracker.com/id?1018770http://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2007/3895http://www.vupen.com/english/advisories/2008/0609http://www.vupen.com/english/advisories/2008/1856/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/36946https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11592http://dev2dev.bea.com/pub/advisory/272http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlhttp://secunia.com/advisories/27206http://secunia.com/advisories/27261http://secunia.com/advisories/27693http://secunia.com/advisories/27716http://secunia.com/advisories/27804http://secunia.com/advisories/28777http://secunia.com/advisories/28880http://secunia.com/advisories/29042http://secunia.com/advisories/29858http://secunia.com/advisories/29897http://secunia.com/advisories/30676http://secunia.com/advisories/30780http://security.gentoo.org/glsa/glsa-200804-28.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-103073-1http://support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200804-20.xmlhttp://www.gentoo.org/security/en/glsa/glsa-200806-11.xmlhttp://www.novell.com/linux/security/advisories/2007_55_java.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0963.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1041.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0132.htmlhttp://www.securityfocus.com/archive/1/482926/100/0/threadedhttp://www.securityfocus.com/bid/25920http://www.securitytracker.com/id?1018770http://www.vmware.com/security/advisories/VMSA-2008-0010.htmlhttp://www.vupen.com/english/advisories/2007/3895http://www.vupen.com/english/advisories/2008/0609http://www.vupen.com/english/advisories/2008/1856/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/36946https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11592
2007-10-06
Published