CVE-2009-1094JDK vulnerability

9 documents7 sources
Severity
10.0CRITICALNVD
EPSS
6.3%
top 9.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 25
Latest updateMay 2

Description

Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

NVDsun/jdk1.5.0+3
NVDsun/jre1.5.0+48
NVDsun/sdk1.3.1_24+48

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5w5h-m7x5-fq48: Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 52022-05-02
OSV
CVE-2011-1094: kio/kio/tcpslavebase2011-03-16
CVEList
CVE-2009-1094: Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 52009-03-25

📋Vendor Advisories

3
Red Hat
kdelibs: SSL certificate for IP address accepted as valid for hosts that resolve to the IP2011-01-31
Ubuntu
OpenJDK vulnerabilities2009-03-26
Red Hat
OpenJDK LDAP client remote code execution (6737315)2009-03-25

💬Community

1
Bugzilla
CVE-2009-1094 OpenJDK LDAP client remote code execution (6737315)2009-03-13
CVE-2009-1094 — SUN JDK vulnerability | cvebase