Information Disclosure Vulnerability in Java Runtime Environment by Sun Microsystems
CVE-2009-3880

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
9 November 2009

Summary

The Abstract Window Toolkit (AWT) in the Java Runtime Environment (JRE) does not adequately restrict the objects sent to loggers. This flaw enables attackers to potentially access sensitive information through specific vectors related to Component, KeyboardFocusManager, and DefaultKeyboardFocusManager functions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.