CVE-2009-1102: Code Injection
Unspecified vulnerability in the Virtual Machine in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "code generation."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to systems running JDK/JRE 6 Update 12 and earlier (for example, apply firewall rules, network segmentation, or WAF policies) and isolate them from untrusted networks until a vendor-provided fix is available.
- Operational
Identify and inventory all systems running Java SE Development Kit (JDK) or Java Runtime Environment (JRE) 6 Update 12 and earlier.
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1102?
CVE-2009-1102 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2009-1102?
To address CVE-2009-1102, users should upgrade to the latest version of Java SE Development Kit or Java Runtime Environment that is not affected by this vulnerability.
What type of attackers can exploit CVE-2009-1102?
CVE-2009-1102 can be exploited by remote attackers who can send specially crafted input to the affected Java installations.
What are the potential impacts of CVE-2009-1102?
The impacts of CVE-2009-1102 may include unauthorized access to local files and execution of arbitrary code on the victim's machine.
Which software versions are affected by CVE-2009-1102?
CVE-2009-1102 affects Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier.