PT-2010-4924 · Oracle+2 · Java For Business+4
Matthias Kaiser
+1
·
Published
2010-10-12
·
Updated
2017-09-19
·
CVE-2010-3563
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Java SE and Java for Business 6 Update 21
Description
The issue affects the confidentiality, integrity, and availability of the system, allowing remote attackers to exploit it via unknown vectors. It is reportedly related to how Web Start retrieves security policies, involving
BasicServiceImpl and potentially forged policies that bypass sandbox restrictions.Recommendations
For Oracle Java SE and Java for Business 6 Update 21, consider disabling the
BasicServiceImpl until a patch is available to prevent potential remote code execution. Restrict access to Web Start to minimize the risk of exploitation. Avoid using forged policies that could bypass sandbox restrictions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp-Ux
Java Platform
Java For Business
Oracle Java Se
Red Hat