PT-2010-4924 · Oracle+2 · Java For Business+4

Matthias Kaiser

+1

·

Published

2010-10-12

·

Updated

2017-09-19

·

CVE-2010-3563

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Java SE and Java for Business 6 Update 21
Description The issue affects the confidentiality, integrity, and availability of the system, allowing remote attackers to exploit it via unknown vectors. It is reportedly related to how Web Start retrieves security policies, involving BasicServiceImpl and potentially forged policies that bypass sandbox restrictions.
Recommendations For Oracle Java SE and Java for Business 6 Update 21, consider disabling the BasicServiceImpl until a patch is available to prevent potential remote code execution. Restrict access to Web Start to minimize the risk of exploitation. Avoid using forged policies that could bypass sandbox restrictions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-3563
HPSBUX02608
RHSA-2010:0770
RHSA-2010:0987
RHSA-2010_0987
RHSA-2011:0880
ZDI-10-202

Affected Products

Hp-Ux
Java Platform
Java For Business
Oracle Java Se
Red Hat