CVE-2008-5347JDK vulnerability

CWE-2646 documents6 sources
Severity
7.5HIGHNVD
EPSS
2.8%
top 13.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 5
Latest updateMay 17

Description

Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applications to gain privileges via vectors related to access to inner classes in the (1) JAX-WS and (2) JAXB packages.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDsun/jdk6+1
NVDsun/jre6+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-982w-2wqp-q964: Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applica2022-05-17
CVEList
CVE-2008-5347: Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applica2008-12-05

📋Vendor Advisories

2
Ubuntu
openjdk-6 vulnerabilities2009-01-27
Red Hat
OpenJDK applet privilege escalation via JAX package access (6592792)2008-12-03

💬Community

1
Bugzilla
CVE-2008-5347 OpenJDK applet privilege escalation via JAX package access (6592792)2008-11-19
CVE-2008-5347 — SUN JDK vulnerability | cvebase