Improper Access Control in Sun Java SE and OpenJDK
CVE-2009-2689

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
10 August 2009

Summary

The vulnerability involves the JDK13Services.getProviders method in Sun Java SE versions 5.0 prior to Update 20 and 6 prior to Update 15, as well as in OpenJDK. It allows context-dependent attackers to bypass access control restrictions through untrusted applets or applications. This flaw could potentially expose sensitive data or facilitate unauthorized actions within the Java environment.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.