First published: Wed Mar 25 2009(Updated: )
Unspecified vulnerability in the Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "deserializing applets," aka CR 6646860.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1103 is classified as a high severity vulnerability due to its potential for remote code execution.
To mitigate CVE-2009-1103, update the Java SE Development Kit (JDK) and Java Runtime Environment (JRE) to the latest version.
CVE-2009-1103 affects Java SE Development Kit (JDK) and Java Runtime Environment (JRE) versions 5.0 Update 17 and earlier, 6 Update 12 and earlier, 1.4.2_19 and earlier, and 1.3.1_24 and earlier.
Yes, CVE-2009-1103 is exploitable, allowing remote attackers to access files and execute arbitrary code.
If you are required to use an affected version, consider implementing additional security measures such as disabling the Java Plug-in in the browser.