cbcvebase.
CVE-2010-3860
published 2010-12-08

CVE-2010-3860: IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows…

PriorityP422medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
3.00%
85.8th percentile
IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to obtain sensitive information including (1) user.name, (2) user.home, and (3) java.home system properties, and other sensitive information such as installation directories.

Affected

8 ranges
VendorProductVersion rangeFixed in
redhaticedtea<= 1.9.1
redhaticedtea
redhaticedtea
redhaticedtea
redhaticedtea
redhaticedtea
redhaticedtea
redhaticedtea

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.