CVE-2009-3865
published 2009-11-05CVE-2009-3865: The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers…
PriorityP348critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
9.40%
94.8th percentile
The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752)
vendor_redhat·2009-11-03·CVSS 9.3
CVE-2009-3865 [CRITICAL] java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752)
java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752)
The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.
GHSA
GHSA-vm5p-j4c4-475p: The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote at
ghsa_unreviewed·2022-05-02
CVE-2009-3865 [HIGH] CWE-94 GHSA-vm5p-j4c4-475p: The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote at
The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3865 java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752)
bugzilla·2009-11-05·CVSS 9.3
CVE-2009-3865 [CRITICAL] CVE-2009-3865 java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752)
CVE-2009-3865 java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752)
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3865 to
the following vulnerability:
The launch method in the Deployment Toolkit plugin in Java Runtime
Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17
allows remote attackers to execute arbitrary commands via a crafted
web page, aka Bug Id 6869752.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3865
http://java.sun.com/javase/6/webnotes/6u17.html
http://sunsolve.sun.com/search/document.do?assetkey=1-66-269869-1
http://www.securityfocus.com/bid/36881
http://secunia.com/advisories/37231
http://www.vupen.com/english/advisories/2009/3131
Discussion:
This issue does NOT affect the versions of the java-1.5.0-sun p
Bugzilla
CVE-2009-3865 JRE Deployment Toolkit plugin "launch" method vulnerable to exploits (6869752)
bugzilla·2009-11-04·CVSS 9.3
CVE-2009-3865 [CRITICAL] CVE-2009-3865 JRE Deployment Toolkit plugin "launch" method vulnerable to exploits (6869752)
CVE-2009-3865 JRE Deployment Toolkit plugin "launch" method vulnerable to exploits (6869752)
aka http://sunsolve.sun.com/search/document.do?assetkey=1-66-269869-1
"A command execution vulnerability in the Java Runtime Environment
Deployment Toolkit may be leveraged to execute arbitrary code. This may
occur as the result of a user of the Java Runtime Environment viewing a
specially crafted web page that exploits this vulnerability."
Discussion:
*** This bug has been marked as a duplicate of bug 533211 ***
http://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.htmlhttp://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/37231http://secunia.com/advisories/37239http://secunia.com/advisories/37386http://secunia.com/advisories/37581http://secunia.com/advisories/37841http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-269869-1http://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.redhat.com/support/errata/RHSA-2009-1694.htmlhttp://www.securityfocus.com/bid/36881http://www.securitytracker.com/id?1023244http://www.vupen.com/english/advisories/2009/3131https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7562http://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.htmlhttp://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/37231http://secunia.com/advisories/37239http://secunia.com/advisories/37386http://secunia.com/advisories/37581http://secunia.com/advisories/37841http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-269869-1http://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.redhat.com/support/errata/RHSA-2009-1694.htmlhttp://www.securityfocus.com/bid/36881http://www.securitytracker.com/id?1023244http://www.vupen.com/english/advisories/2009/3131https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7562
2009-11-05
Published