CVE-2007-2435
Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, allows remote attackers to perform unauthorized actions via an application that grants privileges to itself, related to "Incorrect Use…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, allows remote attackers to perform unauthorized actions via an application that grants privileges to itself, related to "Incorrect Use of System Classes" and probably related to support for JNLP files.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.96% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- sun/java enterprise system · sun/jre · sun/sdk
- Source
- cve@mitre.org
References
- http://dev2dev.bea.com/pub/advisory/241
- http://docs.info.apple.com/article.html?artnum=307177
- http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html
- http://osvdb.org/35483
- http://secunia.com/advisories/25069Patch, Vendor Advisory
- http://secunia.com/advisories/25283
- http://secunia.com/advisories/25413
- http://secunia.com/advisories/25474
- http://secunia.com/advisories/25832
- http://secunia.com/advisories/26311
- http://secunia.com/advisories/26369
- http://secunia.com/advisories/28115
- http://secunia.com/advisories/29858
- http://secunia.com/advisories/30780
- http://security.gentoo.org/glsa/glsa-200706-08.xml
- http://security.gentoo.org/glsa/glsa-200804-28.xml
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102881-1Patch, Vendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2007-199.htm
- http://www.gentoo.org/security/en/glsa/glsa-200705-23.xml
- http://www.gentoo.org/security/en/glsa/glsa-200804-20.xml
- http://www.gentoo.org/security/en/glsa/glsa-200806-11.xml
- http://www.redhat.com/support/errata/RHSA-2007-0817.html
- http://www.redhat.com/support/errata/RHSA-2007-0829.html
- http://www.redhat.com/support/errata/RHSA-2008-0261.html
- http://www.securityfocus.com/bid/23728Patch
- http://www.securitytracker.com/id?1017986
- http://www.vupen.com/english/advisories/2007/1598
- http://www.vupen.com/english/advisories/2007/1814
- http://www.vupen.com/english/advisories/2007/4224
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33984
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.