CVE-2009-3864
The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 22.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 22.48% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows · sun/jdk · sun/jre
- Source
- cve@mitre.org
References
- http://java.sun.com/javase/6/webnotes/6u17.html
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.html
- http://secunia.com/advisories/37231Vendor Advisory
- http://secunia.com/advisories/37239
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-269868-1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/36881Patch
- http://www.vupen.com/english/advisories/2009/3131Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6753
- http://java.sun.com/javase/6/webnotes/6u17.html
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.html
- http://secunia.com/advisories/37231Vendor Advisory
- http://secunia.com/advisories/37239
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-269868-1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/36881Patch
- http://www.vupen.com/english/advisories/2009/3131Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6753
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.