CVE-2009-3728Path Traversal in JRE

CWE-22Path Traversal6 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 34.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 9
Latest updateMay 2

Description

Directory traversal vulnerability in the ICC_Profile.getInstance method in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local International Color Consortium (ICC) profile files via a .. (dot dot) in a pathname, aka Bug Id 6631533.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDsun/jre1.5.0, 1.6.0+1

🔴Vulnerability Details

2
GHSA
GHSA-54cg-rgh7-pj5q: Directory traversal vulnerability in the ICC_Profile2022-05-02
CVEList
CVE-2009-3728: Directory traversal vulnerability in the ICC_Profile2009-11-09

📋Vendor Advisories

2
Ubuntu
OpenJDK vulnerabilities2009-11-12
Red Hat
OpenJDK ICC_Profile file existence detection information leak (6631533)2009-11-03

💬Community

1
Bugzilla
CVE-2009-3728 OpenJDK ICC_Profile file existence detection information leak (6631533)2009-10-21
CVE-2009-3728 — Path Traversal in SUN JRE | cvebase