Local File Disclosure Weakness in Sun Java SE and OpenJDK Products
CVE-2009-3884
Currently unrated
What is CVE-2009-3884?
The TimeZone.getTimeZone method in Sun Java SE versions prior to Update 22 and Java SE 6 prior to Update 17, along with OpenJDK, contains a security flaw that enables remote attackers to ascertain the existence of local files. This vulnerability arises from improper handling of zoneinfo (tz) files, which could potentially expose sensitive filesystem information.