CVE-2008-3551
Multiple unspecified vulnerabilities in Sun Java Platform Micro Edition (aka Java ME, J2ME, or mobile Java), as distributed in Sun Wireless Toolkit 2.5.2, allow remote attackers to execute arbitrary code via unknown vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in Sun Java Platform Micro Edition (aka Java ME, J2ME, or mobile Java), as distributed in Sun Wireless Toolkit 2.5.2, allow remote attackers to execute arbitrary code via unknown vectors. NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a company led by a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.91% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- sun/java platform micro edition · sun/wireless toolkit
- Source
- cve@mitre.org
References
- http://www.security-explorations.com/n2press.htm
- http://www.security-explorations.com/n2srp.htm
- http://www.security-explorations.com/n2vendors.htm
- http://www.security-explorations.com/report_toc.pdf
- http://www.securityfocus.com/archive/1/495224/100/0/threaded
- http://www.securityfocus.com/bid/30591
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44478
- http://www.security-explorations.com/n2press.htm
- http://www.security-explorations.com/n2srp.htm
- http://www.security-explorations.com/n2vendors.htm
- http://www.security-explorations.com/report_toc.pdf
- http://www.securityfocus.com/archive/1/495224/100/0/threaded
- http://www.securityfocus.com/bid/30591
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44478
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.