[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-2672Date: (C)2009-08-05   (M)2024-02-22


The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1022659
http://www.securityfocus.com/archive/1/507985/100/0/threaded
SUNALERT-263409
BID-35943
SECUNIA-36176
SECUNIA-36180
SECUNIA-36199
SECUNIA-36248
SECUNIA-37300
SECUNIA-37386
SECUNIA-37460
ADV-2009-2543
ADV-2009-3316
APPLE-SA-2009-09-03-1
GLSA-200911-02
HPSBUX02476
RHSA-2009:1199
RHSA-2009:1200
RHSA-2009:1201
SUSE-SA:2009:043
SUSE-SA:2009:053
SUSE-SR:2009:016
TA09-294A
http://java.sun.com/j2se/1.5.0/ReleaseNotes.html#150_20
http://java.sun.com/javase/6/webnotes/6u15.html
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1
http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
oval:org.mitre.oval:def:7723
oval:org.mitre.oval:def:9359
sun-jre-proxy-session-hijacking(52337)

CWE    1
CWE-264
OVAL    8
oval:org.secpod.oval:def:400074
oval:org.secpod.oval:def:19702
oval:org.secpod.oval:def:101499
oval:org.secpod.oval:def:700354
...

© SecPod Technologies