CVE-2008-3105
published 2008-07-09CVE-2008-3105: Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers…
PriorityP336high8.3CVSS 2.0
AVNACMAuNCPIPAC
EPSS
4.04%
89.4th percentile
Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to access URLs or cause a denial of service via unknown vectors involving "processing of XML data" by a trusted application.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 5.0 | — |
| sun | jdk | <= 6 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | <= 5.0 | — |
| sun | jre | <= 6 | — |
| sun | jre | — | — |
| sun | jre | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.08.3HIGHAV:N/AC:M/Au:N/C:P/I:P/A:C
vendor_redhat8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vjpx-8gm7-4pxc: Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5
ghsa_unreviewed·2022-05-01·CVSS 8.3
CVE-2008-3106 [HIGH] GHSA-vjpx-8gm7-4pxc: Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5
Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier allows remote attackers to access URLs via unknown vectors involving processing of XML data by an untrusted (1) application or (2) applet, a different vulnerability than CVE-2008-3105.
GHSA
GHSA-p9xp-4jv8-8r8f: Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote a
ghsa_unreviewed·2022-05-01
CVE-2008-3105 [HIGH] GHSA-p9xp-4jv8-8r8f: Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote a
Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to access URLs or cause a denial of service via unknown vectors involving "processing of XML data" by a trusted application.
VMware
VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues
vendor_vmware·2008-10-03·CVSS 6.8
CVE-2008-3103 [MEDIUM] VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues
VMSA-2008-0016: VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues
a. Privilege escalation on 64-bit guest operating systems VMware products emulate hardware functions, like CPU, Memory, and IO. A flaw in VMware's CPU hardware emulation could allow the virtual CPU to jump to an incorrect memory address. Exploitation of this issue on the guest operating system does not lead to a compromise of the host system but could lead to a privilege escalation on guest operating system. An attacker would need to have a user account on the guest operating system. Affected 64-bit Windows and 64-bit FreeBSD guest operating systems and possibly other 64-bit operating systems. The issue does not affect the 64-bit versions of Linux guest operating sy
Red Hat
security flaw
vendor_redhat·2008-07-08·CVSS 8.3
CVE-2008-3106 [HIGH] security flaw
security flaw
Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier allows remote attackers to access URLs via unknown vectors involving processing of XML data by an untrusted (1) application or (2) applet, a different vulnerability than CVE-2008-3105.
Red Hat
OpenJDK JAX-WS unauthorized URL access (6542088)
vendor_redhat·2008-07-08·CVSS 8.3
CVE-2008-3105 [HIGH] OpenJDK JAX-WS unauthorized URL access (6542088)
OpenJDK JAX-WS unauthorized URL access (6542088)
Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to access URLs or cause a denial of service via unknown vectors involving "processing of XML data" by a trusted application.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-3106 security flaw
bugzilla·2018-08-16·CVSS 8.3
CVE-2008-3106 [HIGH] CVE-2008-3106 security flaw
CVE-2008-3106 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier allows remote attackers to access URLs via unknown vectors involving processing of XML data by an untrusted (1) application or (2) applet, a different vulnerability than CVE-2008-3105.
Bugzilla
CVE-2008-3105 CVE-2008-3106 OpenJDK JAX-WS unauthorized URL access (6542088)
bugzilla·2008-06-24·CVSS 8.3
CVE-2008-3105 [HIGH] CVE-2008-3105 CVE-2008-3106 OpenJDK JAX-WS unauthorized URL access (6542088)
CVE-2008-3105 CVE-2008-3106 OpenJDK JAX-WS unauthorized URL access (6542088)
From Sun pre-notification, 6/23/2008
1. 6542088
A vulnerability in the Java™ Runtime Environment with processing XML data may
allow unauthorized access to certain URL resources (such as some files and web
pages) or a Denial of Service (DoS) condition to be created on the system
running the JRE.
For this vulnerability to be exploited, the JAX-WS client or service in a
trusted application needs to process XML data that contains malicious content.
This vulnerability cannot be exploited through an untrusted applet or untrusted
Java Web Start application.
Discussion:
java-1.6.0-openjdk-1.6.0.0-0.16.b09.fc9 has been submitted as an update for Fedora 9
---
java-1.7.0-icedtea-1.7.0.0-0.20.b21.snapshot.fc8 has been
http://lists.apple.com/archives/security-announce//2008/Sep/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.htmlhttp://marc.info/?l=bugtraq&m=122331139823057&w=2http://secunia.com/advisories/31010http://secunia.com/advisories/31600http://secunia.com/advisories/32018http://secunia.com/advisories/32179http://secunia.com/advisories/32180http://secunia.com/advisories/32436http://secunia.com/advisories/33237http://secunia.com/advisories/33238http://secunia.com/advisories/37386http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-238628-1http://support.apple.com/kb/HT3179http://support.avaya.com/elmodocs2/security/ASA-2008-299.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-428.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-507.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-509.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=751014http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=756717http://www.redhat.com/support/errata/RHSA-2008-0594.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0906.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1044.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1045.htmlhttp://www.securityfocus.com/archive/1/497041/100/0/threadedhttp://www.securityfocus.com/bid/30143http://www.securitytracker.com/id?1020457http://www.us-cert.gov/cas/techalerts/TA08-193A.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0016.htmlhttp://www.vupen.com/english/advisories/2008/2056/referenceshttp://www.vupen.com/english/advisories/2008/2740https://exchange.xforce.ibmcloud.com/vulnerabilities/43654https://exchange.xforce.ibmcloud.com/vulnerabilities/43657https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11274http://lists.apple.com/archives/security-announce//2008/Sep/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.htmlhttp://marc.info/?l=bugtraq&m=122331139823057&w=2http://secunia.com/advisories/31010http://secunia.com/advisories/31600http://secunia.com/advisories/32018http://secunia.com/advisories/32179http://secunia.com/advisories/32180http://secunia.com/advisories/32436http://secunia.com/advisories/33237http://secunia.com/advisories/33238http://secunia.com/advisories/37386http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-238628-1http://support.apple.com/kb/HT3179http://support.avaya.com/elmodocs2/security/ASA-2008-299.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-428.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-507.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-509.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=751014http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=756717http://www.redhat.com/support/errata/RHSA-2008-0594.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0906.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1044.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1045.htmlhttp://www.securityfocus.com/archive/1/497041/100/0/threadedhttp://www.securityfocus.com/bid/30143http://www.securitytracker.com/id?1020457http://www.us-cert.gov/cas/techalerts/TA08-193A.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0016.htmlhttp://www.vupen.com/english/advisories/2008/2056/referenceshttp://www.vupen.com/english/advisories/2008/2740https://exchange.xforce.ibmcloud.com/vulnerabilities/43654https://exchange.xforce.ibmcloud.com/vulnerabilities/43657https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11274
2008-07-09
Published