CVE-2009-2689
published 2009-08-10CVE-2009-2689: JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.84%
85.0th percentile
JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | java_se | <= 5.0 | — |
| sun | java_se | <= 6 | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2009-08-11·CVSS 5.0
CVE-2009-0217 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
It was discovered that the XML HMAC signature system did not
correctly check certain lengths. If an attacker sent a truncated
HMAC, it could bypass authentication, leading to potential privilege
escalation. (CVE-2009-0217)
It was discovered that JAR bundles would appear signed if only one element
was signed. If a user were tricked into running a malicious Java applet, a
remote attacker could exploit this to gain access to private information and
potentially run untrusted code. (CVE-2009-1896)
It was discovered that certain variables could leak information. If a
user were tricked into running a malicious Java applet, a remote attacker
could exploit this to gain access to private information and potentially
run untrusted cod
Red Hat
OpenJDK JDK13Services grants unnecessary privileges (6777448)
vendor_redhat·2009-08-05·CVSS 10.0
CVE-2009-2689 [CRITICAL] OpenJDK JDK13Services grants unnecessary privileges (6777448)
OpenJDK JDK13Services grants unnecessary privileges (6777448)
JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.
GHSA
GHSA-vvrm-5g2q-cfmr: JDK13Services
ghsa_unreviewed·2022-05-02
CVE-2009-2689 [HIGH] GHSA-vvrm-5g2q-cfmr: JDK13Services
JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.
No detection rules found.
No public exploits indexed.
http://java.sun.com/j2se/1.5.0/ReleaseNotes.htmlhttp://java.sun.com/javase/6/webnotes/6u15.htmlhttp://lists.apple.com/archives/security-announce/2009/Sep/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlhttp://secunia.com/advisories/36162http://secunia.com/advisories/36180http://secunia.com/advisories/36199http://secunia.com/advisories/37386http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1http://www.mandriva.com/security/advisories?name=MDVSA-2009:209http://www.vupen.com/english/advisories/2009/2543https://bugzilla.redhat.com/show_bug.cgi?id=513222https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9603https://rhn.redhat.com/errata/RHSA-2009-1199.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1201.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.htmlhttp://java.sun.com/j2se/1.5.0/ReleaseNotes.htmlhttp://java.sun.com/javase/6/webnotes/6u15.htmlhttp://lists.apple.com/archives/security-announce/2009/Sep/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlhttp://secunia.com/advisories/36162http://secunia.com/advisories/36180http://secunia.com/advisories/36199http://secunia.com/advisories/37386http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1http://www.mandriva.com/security/advisories?name=MDVSA-2009:209http://www.vupen.com/english/advisories/2009/2543https://bugzilla.redhat.com/show_bug.cgi?id=513222https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9603https://rhn.redhat.com/errata/RHSA-2009-1199.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1201.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html
2009-08-10
Published