CVE-2008-5340JDK vulnerability

CWE-2645 documents5 sources
Severity
10.0CRITICALNVD
EPSS
4.0%
top 11.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 5
Latest updateMay 17

Description

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

NVDsun/jdk5.0+3
NVDsun/jre1.4.2_18+21
NVDsun/sdk1.4.2_18+17

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xxwj-cpv6-f4hc: Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 52022-05-17
CVEList
CVE-2008-5340: Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 52008-12-05

📋Vendor Advisories

1
Red Hat
Java WebStart privilege escalation2008-12-04

💬Community

1
Bugzilla
CVE-2008-5340 Java WebStart privilege escalation2008-12-05
CVE-2008-5340 — SUN JDK vulnerability | cvebase