CVE-2009-2673
published 2009-08-05CVE-2009-2673: The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote…
PriorityP345high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.84%
91.0th percentile
The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | bea_product_suite | — | — |
| sun | java_se | <= 5.0 | — |
| sun | java_se | <= 6 | — |
| sun | jdk | <= 6 | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | <= 6 | — |
| sun | jre | — | — |
| sun | jre | — | — |
| vmware | esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.8HIGH
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2009-08-11·CVSS 5.0
CVE-2009-0217 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
It was discovered that the XML HMAC signature system did not
correctly check certain lengths. If an attacker sent a truncated
HMAC, it could bypass authentication, leading to potential privilege
escalation. (CVE-2009-0217)
It was discovered that JAR bundles would appear signed if only one element
was signed. If a user were tricked into running a malicious Java applet, a
remote attacker could exploit this to gain access to private information and
potentially run untrusted code. (CVE-2009-1896)
It was discovered that certain variables could leak information. If a
user were tricked into running a malicious Java applet, a remote attacker
could exploit this to gain access to private information and potentially
run untrusted cod
Red Hat
OpenJDK information leaks in mutable variables (6588003,6656586,6656610,6656625,6657133,6657619,6657625,6657695,6660049,6660539,6813167)
vendor_redhat·2009-08-05·CVSS 7.8
CVE-2009-2475 [HIGH] OpenJDK information leaks in mutable variables (6588003,6656586,6656610,6656625,6657133,6657619,6657625,6657695,6660049,6660539,6813167)
OpenJDK information leaks in mutable variables (6588003,6656586,6656610,6656625,6657133,6657619,6657625,6657695,6660049,6660539,6813167)
Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3) AccessibleResourceBundle.getContents, (4) ImageReaderSpi.STANDARD_INPUT_TYPE, (5) ImageWriterSpi.STANDARD_OUTPUT_TYPE, (6) the imageio plugins, (7) DnsContext.debug, (8) RmfFileReader/StandardMidiFileWriter.types, (9) AbstractSaslImpl.logger, (10) Synth.Region.uiToRegionMap/lowerCaseNameMap, (11) the Introspector class and a cache of BeanInfo, and (12) JAX-WS, a different vulner
Red Hat
OpenJDK proxy mechanism allows non-authorized socket connections (6801497)
vendor_redhat·2009-08-05·CVSS 7.5
CVE-2009-2673 [HIGH] OpenJDK proxy mechanism allows non-authorized socket connections (6801497)
OpenJDK proxy mechanism allows non-authorized socket connections (6801497)
The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.
GHSA
GHSA-9r76-mhm8-f3q4: Unspecified vulnerability in the JRockit component in BEA Product Suite R27
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-3403 [MEDIUM] GHSA-9r76-mhm8-f3q4: Unspecified vulnerability in the JRockit component in BEA Product Suite R27
Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.4: JRE/JDK, 1.4.2, 5, and, and 6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this issue subsumes CVE-2009-2670, CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2674, CVE-2009-2675, and CVE-2009-2676.
GHSA
GHSA-2vx8-fp5p-f94q: Sun Java SE 5
ghsa_unreviewed·2022-05-02·CVSS 7.5
CVE-2009-2475 [HIGH] CWE-200 GHSA-2vx8-fp5p-f94q: Sun Java SE 5
Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3) AccessibleResourceBundle.getContents, (4) ImageReaderSpi.STANDARD_INPUT_TYPE, (5) ImageWriterSpi.STANDARD_OUTPUT_TYPE, (6) the imageio plugins, (7) DnsContext.debug, (8) RmfFileReader/StandardMidiFileWriter.types, (9) AbstractSaslImpl.logger, (10) Synth.Region.uiToRegionMap/lowerCaseNameMap, (11) the Introspector class and a cache of BeanInfo, and (12) JAX-WS, a different vulnerability than CVE-2009-2673.
GHSA
GHSA-4rjf-p9gv-749h: The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5
ghsa_unreviewed·2022-05-02
CVE-2009-2673 [HIGH] GHSA-4rjf-p9gv-749h: The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5
The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.
No detection rules found.
No public exploits indexed.
http://java.sun.com/j2se/1.5.0/ReleaseNotes.html#150_20http://java.sun.com/javase/6/webnotes/6u15.htmlhttp://lists.apple.com/archives/security-announce/2009/Sep/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.htmlhttp://marc.info/?l=bugtraq&m=125787273209737&w=2http://osvdb.org/56785http://secunia.com/advisories/36162http://secunia.com/advisories/36176http://secunia.com/advisories/36180http://secunia.com/advisories/36199http://secunia.com/advisories/36248http://secunia.com/advisories/37300http://secunia.com/advisories/37386http://secunia.com/advisories/37460http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-263409-1http://www.mandriva.com/security/advisories?name=MDVSA-2009:209http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.htmlhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/35943http://www.securitytracker.com/id?1022659http://www.us-cert.gov/cas/techalerts/TA09-294A.htmlhttp://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/2543http://www.vupen.com/english/advisories/2009/3316https://exchange.xforce.ibmcloud.com/vulnerabilities/52338https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10263https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8558https://rhn.redhat.com/errata/RHSA-2009-1199.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1200.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1201.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.htmlhttp://java.sun.com/j2se/1.5.0/ReleaseNotes.html#150_20http://java.sun.com/javase/6/webnotes/6u15.htmlhttp://lists.apple.com/archives/security-announce/2009/Sep/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.htmlhttp://marc.info/?l=bugtraq&m=125787273209737&w=2http://osvdb.org/56785http://secunia.com/advisories/36162http://secunia.com/advisories/36176http://secunia.com/advisories/36180http://secunia.com/advisories/36199http://secunia.com/advisories/36248http://secunia.com/advisories/37300http://secunia.com/advisories/37386http://secunia.com/advisories/37460http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-263409-1http://www.mandriva.com/security/advisories?name=MDVSA-2009:209http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.htmlhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/35943http://www.securitytracker.com/id?1022659http://www.us-cert.gov/cas/techalerts/TA09-294A.htmlhttp://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2009/2543http://www.vupen.com/english/advisories/2009/3316https://exchange.xforce.ibmcloud.com/vulnerabilities/52338https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10263https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8558https://rhn.redhat.com/errata/RHSA-2009-1199.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1200.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1201.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html
2009-08-05
Published