CVE-2007-5238: Low severity Java Development Kit (JDK) vulnerability
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.215 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka "three vulnerabilities."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5238?
CVE-2007-5238 is considered a moderate severity vulnerability due to improper enforcement of access restrictions for untrusted applications.
How do I fix CVE-2007-5238?
To fix CVE-2007-5238, upgrade your Java Runtime Environment (JRE) or Java Development Kit (JDK) to a version later than 6 Update 2, 5.0 Update 12, or 1.4.2_15.
Which versions are affected by CVE-2007-5238?
CVE-2007-5238 affects Sun JDK and JRE versions 1.6.0 and earlier, as well as earlier versions of 5.0 and 1.4.2.
What types of applications are vulnerable to CVE-2007-5238?
CVE-2007-5238 affects untrusted Java Web Start applications that can bypass access restrictions, potentially leading to sensitive information exposure.
Is user interaction required for CVE-2007-5238 exploitation?
Yes, exploitation of CVE-2007-5238 requires user-assisted actions to trigger the vulnerability.