CVE-2008-3105JDK vulnerability

CWE-26410 documents5 sources
Severity
8.3HIGHNVD
NVD4.3
EPSS
22.5%
top 4.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 9
Latest updateMay 1

Description

Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to access URLs or cause a denial of service via unknown vectors involving "processing of XML data" by a trusted application.

CVSS vector

AV:N/AC:M/C:P/I:P/A:CExploitability: 8.6 | Impact: 8.5

Affected Packages2 packages

NVDsun/jdk5.0+3
NVDsun/jre5.0+3

Patches

🔴Vulnerability Details

4
GHSA
GHSA-vjpx-8gm7-4pxc: Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 52022-05-01
GHSA
GHSA-p9xp-4jv8-8r8f: Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote a2022-05-01
CVEList
CVE-2008-3105: Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote a2008-07-09
CVEList
CVE-2008-3106: Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 52008-07-09

📋Vendor Advisories

2
Red Hat
security flaw2008-07-08
Red Hat
OpenJDK JAX-WS unauthorized URL access (6542088)2008-07-08

💬Community

2
Bugzilla
CVE-2008-3106 security flaw2018-08-16
Bugzilla
CVE-2008-3105 CVE-2008-3106 OpenJDK JAX-WS unauthorized URL access (6542088)2008-06-24
CVE-2008-3105 — SUN JDK vulnerability | cvebase