SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-3864

The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which…

HIGH 7.5EPSS 22.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 22.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
22.48% probability · 98th percentile
CISA KEV
Not listed
Affected
microsoft/windows · sun/jdk · sun/jre
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.