CVE-2006-0615: Medium severity Java Development Kit (JDK) vulnerability
Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 4 and earlier, SDK and JRE 1.4.x through 1.4.209 allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "second and third issues."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0615?
CVE-2006-0615 has a critical severity due to the potential for remote attackers to bypass Java sandbox security.
How do I fix CVE-2006-0615?
To mitigate CVE-2006-0615, upgrade to a non-vulnerable version of the Sun Java JDK or JRE.
Which versions are affected by CVE-2006-0615?
CVE-2006-0615 affects Sun Java JDK and JRE 5.0 Update 4 and earlier, as well as SDK and JRE 1.4.x up to 1.4.2_09.
What types of attacks are possible due to CVE-2006-0615?
CVE-2006-0615 could allow attackers to leverage reflection APIs to gain elevated privileges.
Is there a workaround for CVE-2006-0615 if I cannot upgrade?
There are no recommended workarounds for CVE-2006-0615, making an upgrade the best option.