CVE-2010-3860Sensitive Information Exposure in Redhat Icedtea

Severity
5.0MEDIUMNVD
EPSS
1.5%
top 18.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateMay 17

Description

IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to obtain sensitive information including (1) user.name, (2) user.home, and (3) java.home system properties, and other sensitive information such as installation directories.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDredhat/icedtea1.9.1+7

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pqr4-2v59-c8vx: IcedTea 12022-05-17
CVEList
CVE-2010-3860: IcedTea 12010-12-08

📋Vendor Advisories

2
Ubuntu
OpenJDK vulnerability2010-11-30
Red Hat
IcedTea System property information leak via public static2010-11-24

💬Community

2
Bugzilla
CVE-2010-3860 IcedTea System property information leak via public static [fedora-all]2010-12-01
Bugzilla
CVE-2010-3860 IcedTea System property information leak via public static2010-10-22
CVE-2010-3860 — Sensitive Information Exposure | cvebase