First published: Thu Apr 01 2010(Updated: )
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sun JRE | =1.6.0-update_3 | |
Sun JRE | =1.6.0-update_5 | |
Sun JRE | =1.6.0-update_13 | |
Sun JRE | =1.6.0-update_1 | |
Sun JRE | =1.6.0-update_2 | |
Sun JRE | =1.6.0-update_16 | |
Sun JRE | =1.6.0-update_15 | |
Sun JRE | =1.6.0-update_6 | |
Sun JRE | =1.6.0 | |
Sun JRE | =1.6.0-update_10 | |
Sun JRE | =1.6.0-update_17 | |
Sun JRE | <=1.6.0 | |
Sun JRE | =1.6.0-update_7 | |
Sun JRE | =1.6.0-update_14 | |
Sun JRE | =1.6.0-update_4 | |
Sun JRE | =1.6.0-update_12 | |
Sun JRE | =1.6.0-update_11 | |
Sun JDK | =1.6.0-update_4 | |
Sun JDK | =1.6.0-update_7 | |
Sun JDK | =1.6.0-update_13 | |
Sun JDK | =1.6.0-update_3 | |
Sun JDK | =1.6.0-update_11 | |
Sun JDK | =1.6.0-update_10 | |
Sun JDK | =1.6.0-update_14 | |
Sun JDK | =1.6.0 | |
Sun JDK | =1.6.0-update_17 | |
Sun JDK | =1.6.0-update_5 | |
Sun JDK | =1.6.0-update2 | |
Sun JDK | =1.6.0-update1_b06 | |
Sun JDK | =1.6.0-update_16 | |
Sun JDK | =1.6.0-update1 | |
Sun JDK | <=1.6.0 | |
Sun JDK | =1.6.0-update_15 | |
Sun JDK | =1.6.0-update_12 | |
Sun JDK | =1.6.0-update_6 | |
Sun JDK | =1.5.0-update20 | |
Sun JDK | =1.5.0-update15 | |
Sun JDK | =1.5.0-update18 | |
Sun JDK | =1.5.0-update3 | |
Sun JDK | <=1.5.0 | |
Sun JDK | =1.5.0-update21 | |
Sun JDK | =1.5.0-update11 | |
Sun JDK | =1.5.0-update16 | |
Sun JDK | =1.5.0-update17 | |
Sun JDK | =1.5.0-update9 | |
Sun JDK | =1.5.0-update6 | |
Sun JDK | =1.5.0-update14 | |
Sun JDK | =1.5.0-update1 | |
Sun JDK | =1.5.0-update4 | |
Sun JDK | =1.5.0-update7 | |
Sun JDK | =1.5.0 | |
Sun JDK | =1.5.0-update12 | |
Sun JDK | =1.5.0-update5 | |
Sun JDK | =1.5.0-update2 | |
Sun JDK | =1.5.0-update19 | |
Sun JDK | =1.5.0-update13 | |
Sun JDK | =1.5.0-update8 | |
Sun JDK | =1.5.0-update10 | |
Sun JRE | =1.5.0 | |
Sun JRE | <=1.5.0 | |
Sun JRE | =1.5.0-update18 | |
Sun JRE | =1.5.0-update2 | |
Sun JRE | =1.5.0-update13 | |
Sun JRE | =1.5.0-update12 | |
Sun JRE | =1.5.0-update8 | |
Sun JRE | =1.5.0-update16 | |
Sun JRE | =1.5.0-update21 | |
Sun JRE | =1.5.0-update11 | |
Sun JRE | =1.5.0-update15 | |
Sun JRE | =1.5.0-update7 | |
Sun JRE | =1.5.0-update3 | |
Sun JRE | =1.5.0-update20 | |
Sun JRE | =1.5.0-update5 | |
Sun JRE | =1.5.0-update14 | |
Sun JRE | =1.5.0-update6 | |
Sun JRE | =1.5.0-update9 | |
Sun JRE | =1.5.0-update1 | |
Sun JRE | =1.5.0-update19 | |
Sun JRE | =1.5.0-update10 | |
Sun JRE | =1.5.0-update4 | |
Sun JRE | =1.5.0-update17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.