CVE-2008-3103JDK vulnerability

CWE-2648 documents6 sources
Severity
9.3CRITICALNVD
EPSS
21.9%
top 4.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 9
Latest updateMay 1

Description

Unspecified vulnerability in the Java Management Extensions (JMX) management agent in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier, when local monitoring is enabled, allows remote attackers to "perform unauthorized operations" via unspecified vectors.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDsun/jdk5.0+3
NVDsun/jre5.0+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5qfv-7x2h-3988: Unspecified vulnerability in the Java Management Extensions (JMX) management agent in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and2022-05-01
CVEList
CVE-2008-3103: Unspecified vulnerability in the Java Management Extensions (JMX) management agent in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and2008-07-09

💥Exploits & PoCs

3
Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Negotiate ProcessID Function Table Dereference (MS09-050) (Metasploit)2010-07-03
Exploit-DB
Microsoft Windows 7/2008 R2 - Remote Kernel Crash2009-11-11
Exploit-DB
Microsoft Windows Vista/7 - SMB2.0 Negotiate Protocol Request Remote Blue Screen of Death (MS07-063)2009-09-09

📋Vendor Advisories

1
Red Hat
OpenJDK JMX allows illegal operations with local monitoring (6332953)2008-07-08

💬Community

1
Bugzilla
CVE-2008-3103 OpenJDK JMX allows illegal operations with local monitoring (6332953)2008-06-24
CVE-2008-3103 — SUN JDK vulnerability | cvebase