CVE-2008-3105 — JDK vulnerability
Severity
8.3HIGHNVD
NVD4.3
EPSS
22.5%
top 4.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 9
Latest updateMay 1
Description
Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to access URLs or cause a denial of service via unknown vectors involving "processing of XML data" by a trusted application.
CVSS vector
AV:N/AC:M/C:P/I:P/A:CExploitability: 8.6 | Impact: 8.5
Patches
🔴Vulnerability Details
4GHSA▶
GHSA-vjpx-8gm7-4pxc: Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5↗2022-05-01
GHSA▶
GHSA-p9xp-4jv8-8r8f: Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote a↗2022-05-01
CVEList▶
CVE-2008-3105: Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote a↗2008-07-09
CVEList▶
CVE-2008-3106: Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5↗2008-07-09