CVE-2009-3880: Medium severity sun java runtime environment (jre) vulnerability
The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitive information via vectors related to the implementation of Component, KeyboardFocusManager, and DefaultKeyboardFocusManager, aka Bug Id 6664512.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3880?
CVE-2009-3880 is rated as a medium severity vulnerability.
How do I fix CVE-2009-3880?
To fix CVE-2009-3880, you should upgrade to Java Runtime Environment 5.0 Update 22 or later, or 6 Update 17 or later.
What systems are affected by CVE-2009-3880?
CVE-2009-3880 affects multiple versions of Sun Java SE 5.0 and 6, along with OpenJDK.
What type of vulnerability is CVE-2009-3880?
CVE-2009-3880 is an information disclosure vulnerability in the Abstract Window Toolkit (AWT) of Java.
Can CVE-2009-3880 lead to data breaches?
Yes, CVE-2009-3880 can potentially allow attackers to gain access to sensitive information, leading to data breaches.