PT-2010-4914 · Oracle+2 · Java Se+4

Publicado

2010-10-13

·

Atualizado

2018-10-30

·

CVE-2010-3553

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Java SE and Java for Business versions 6 Update 21, 5.0 Update 25, 1.4.2 27, and 1.3.1 28
Description The issue affects the confidentiality, integrity, and availability of the system, allowing remote attackers to exploit it via unknown vectors. It is reportedly related to unsafe reflection involving the UIDefault.ProxyLazyValue class in the Swing component.
Recommendations For Oracle Java SE and Java for Business version 6 Update 21, update to a newer version to mitigate the risk. For Oracle Java SE and Java for Business version 5.0 Update 25, update to a newer version to mitigate the risk. For Oracle Java SE and Java for Business version 1.4.2 27, update to a newer version to mitigate the risk. For Oracle Java SE and Java for Business version 1.3.1 28, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the Swing component until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-3553
HPSBUX02608
RHSA-2010:0768
RHSA-2010:0770
RHSA-2010:0786
RHSA-2010:0865
RHSA-2010:0986
RHSA-2010:0987
RHSA-2010_0768
RHSA-2010_0865
RHSA-2010_0987
RHSA-2011:0169
RHSA-2011:0880
RHSA-2011_0169

Produtos afetados

Hp-Ux
Java Platform
Java Se
Java For Business
Red Hat