PT-2011-1574 · Oracle+1 · Java Runtime Environment+2

Published

2011-02-17

·

Updated

2017-12-22

·

CVE-2010-4470

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Java Runtime Environment (JRE) versions prior to 6 Update 23
Description The issue allows remote attackers to affect availability via unknown vectors related to JAXP and unspecified APIs. It is also claimed by a downstream vendor to be related to "Features set on SchemaFactory not inherited by Validator," although Oracle has not commented on this.
Recommendations For versions prior to 6 Update 23, update to a version that is not affected by this issue. As a temporary workaround, consider restricting access to JAXP and unspecified APIs until a patch is available. Avoid using the SchemaFactory and Validator classes in the affected API endpoints until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-4470
DSA-2224-1
RHSA-2011:0281
RHSA-2011:0282
RHSA-2011_0281
RHSA-2011_0282

Affected Products

Java Platform
Java Runtime Environment
Red Hat