First published: Wed Jul 09 2008(Updated: )
Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to access URLs or cause a denial of service via unknown vectors involving "processing of XML data" by a trusted application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun JRE | =6-update_3 | |
Sun JRE | =6-update_4 | |
Sun JDK | =6-update_1 | |
Sun JDK | =6-update_3 | |
Sun JRE | =6-update_2 | |
Sun JDK | =6-update_4 | |
Sun JRE | <=6 | |
Sun JRE | =6-update_5 | |
Sun JDK | <=6 | |
Sun JDK | =6-update_2 | |
Sun JRE | =6-update_1 | |
Sun JDK | =6-update_5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3105 has a high severity rating due to the potential for remote attackers to access sensitive URLs or cause a denial of service.
To mitigate CVE-2008-3105, update your JDK or JRE to a version later than 6 Update 6.
CVE-2008-3105 affects applications that utilize the JAX-WS client and service in Java Runtime Environment versions 6 Update 6 and earlier.
Yes, CVE-2008-3105 can be exploited remotely, allowing attackers to potentially gain access to sensitive data.
Java versions 6 Update 1 through 6 Update 6 in both JDK and JRE are vulnerable to CVE-2008-3105.