SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-5341

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted JWS applications to obtain the pathname of the JWS cache and the application…

MEDIUM 5.0EPSS 3.01%

Does this matter?

Lower severity and a low EPSS score (3.01%). Track it; it rarely justifies an emergency change on its own.

Description

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted JWS applications to obtain the pathname of the JWS cache and the application username via unknown vectors, aka CR 6727071.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
3.01% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
sun/jdk · sun/jre · sun/sdk
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.