Improper Access Control in Sun Java SE and OpenJDK
CVE-2009-2689
Currently unrated
Summary
The vulnerability involves the JDK13Services.getProviders method in Sun Java SE versions 5.0 prior to Update 20 and 6 prior to Update 15, as well as in OpenJDK. It allows context-dependent attackers to bypass access control restrictions through untrusted applets or applications. This flaw could potentially expose sensitive data or facilitate unauthorized actions within the Java environment.
References
EPSS Score
7% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved