PT-2008-6465 · Oracle+1 · Sun Jre+5

Published

2008-12-05

·

Updated

2017-09-29

·

CVE-2008-5341

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Java Web Start and Java Plug-in with Sun JDK and JRE versions prior to 6 Update 11 Java Web Start and Java Plug-in with Sun JDK and JRE 5.0 versions prior to 5.0 Update 17
Description The issue allows untrusted Java Web Start applications to obtain the pathname of the Java Web Start cache and the application username via unknown vectors.
Recommendations For Java Web Start and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier, update to version 6 Update 11 or later. For Java Web Start and Java Plug-in with Sun JDK and JRE 5.0 Update 16 and earlier, update to version 5.0 Update 17 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5341
HPSBUX02411
RHSA-2008:1018
RHSA-2008:1025
RHSA-2009:0016
RHSA-2009:0369

Affected Products

Hp-Ux
Java Platform
Java Plug-In
Java Web Start
Sun Jdk
Sun Jre