First published: Wed Jul 09 2008(Updated: )
Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier allows remote attackers to access URLs via unknown vectors involving processing of XML data by an untrusted (1) application or (2) applet, a different vulnerability than CVE-2008-3105.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Java Development Kit (JDK) | <=5.0 | |
Java Development Kit (JDK) | <=6 | |
Java Development Kit (JDK) | =5.0-update_1 | |
Java Development Kit (JDK) | =5.0-update_10 | |
Java Development Kit (JDK) | =5.0-update_11 | |
Java Development Kit (JDK) | =5.0-update_12 | |
Java Development Kit (JDK) | =5.0-update_13 | |
Java Development Kit (JDK) | =5.0-update_14 | |
Java Development Kit (JDK) | =5.0-update_2 | |
Java Development Kit (JDK) | =5.0-update_3 | |
Java Development Kit (JDK) | =5.0-update_4 | |
Java Development Kit (JDK) | =5.0-update_5 | |
Java Development Kit (JDK) | =5.0-update_6 | |
Java Development Kit (JDK) | =5.0-update_7 | |
Java Development Kit (JDK) | =5.0-update_8 | |
Java Development Kit (JDK) | =5.0-update_9 | |
Java Development Kit (JDK) | =6-update_1 | |
Java Development Kit (JDK) | =6-update_2 | |
Java Development Kit (JDK) | =6-update_3 | |
Java Development Kit (JDK) | =6-update_4 | |
Java Development Kit (JDK) | =6-update_5 | |
Sun Java Runtime Environment (JRE) | <=5.0 | |
Sun Java Runtime Environment (JRE) | <=6 | |
Sun Java Runtime Environment (JRE) | =5.0-update_1 | |
Sun Java Runtime Environment (JRE) | =5.0-update_10 | |
Sun Java Runtime Environment (JRE) | =5.0-update_11 | |
Sun Java Runtime Environment (JRE) | =5.0-update_12 | |
Sun Java Runtime Environment (JRE) | =5.0-update_13 | |
Sun Java Runtime Environment (JRE) | =5.0-update_14 | |
Sun Java Runtime Environment (JRE) | =5.0-update_2 | |
Sun Java Runtime Environment (JRE) | =5.0-update_3 | |
Sun Java Runtime Environment (JRE) | =5.0-update_4 | |
Sun Java Runtime Environment (JRE) | =5.0-update_5 | |
Sun Java Runtime Environment (JRE) | =5.0-update_6 | |
Sun Java Runtime Environment (JRE) | =5.0-update_7 | |
Sun Java Runtime Environment (JRE) | =5.0-update_8 | |
Sun Java Runtime Environment (JRE) | =5.0-update_9 | |
Sun Java Runtime Environment (JRE) | =6-update_1 | |
Sun Java Runtime Environment (JRE) | =6-update_2 | |
Sun Java Runtime Environment (JRE) | =6-update_3 | |
Sun Java Runtime Environment (JRE) | =6-update_4 | |
Sun Java Runtime Environment (JRE) | =6-update_5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3106 has not been assigned a CVSS score, but it allows remote attackers to access URLs, which could lead to significant security concerns.
To mitigate CVE-2008-3106, users should update to a patched version of the Sun Java Runtime Environment (JRE) that is not vulnerable.
CVE-2008-3106 affects Sun JDK and JRE versions 5.0 Update 15 and earlier, as well as 6 Update 6 and earlier.
CVE-2008-3106 could allow an attacker to exploit untrusted applications or applets to access sensitive URLs.
There is no specific workaround for CVE-2008-3106 other than upgrading to a secure version of the JRE.