SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-2670

The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which…

MEDIUM 5.0EPSS 3.29%

Does this matter?

Lower severity and a low EPSS score (3.29%). Track it; it rarely justifies an emergency change on its own.

Description

The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
3.29% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
sun/jdk · sun/jre
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.