First published: Wed Jul 22 2009(Updated: )
JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java SE | <=5.0 | |
Sun Openjdk | ||
Sun Java SE | <=6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.