The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.
http://java.sun.com/j2se/1.5.0/ReleaseNotes.html#150_20
http://java.sun.com/javase/6/webnotes/6u15.html
http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.html
http://marc.info/?l=bugtraq&m=125787273209737&w=2
http://secunia.com/advisories/36176
http://secunia.com/advisories/36180
http://secunia.com/advisories/36199
http://secunia.com/advisories/36248
http://secunia.com/advisories/37300
http://secunia.com/advisories/37386
http://secunia.com/advisories/37460
http://security.gentoo.org/glsa/glsa-200911-02.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-263409-1
http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html
http://www.securityfocus.com/archive/1/507985/100/0/threaded
http://www.securityfocus.com/bid/35943
http://www.securitytracker.com/id?1022659
http://www.us-cert.gov/cas/techalerts/TA09-294A.html
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
http://www.vupen.com/english/advisories/2009/2543
http://www.vupen.com/english/advisories/2009/3316
https://exchange.xforce.ibmcloud.com/vulnerabilities/52337
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7723
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9359
https://rhn.redhat.com/errata/RHSA-2009-1199.html
OR
cpe:2.3:a:sun:jdk:5.0:update_1:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_10:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_11:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_12:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_13:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_14:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_15:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_16:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_17:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_2:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_3:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_4:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_5:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_6:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_7:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_8:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:5.0:update_9:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:6:update_1:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:6:update_10:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:6:update_11:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:6:update_12:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:*:update_13:*:*:*:*:*:* versions up to 6 (inclusive)
cpe:2.3:a:sun:jdk:6:update_2:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:6:update_3:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:6:update_4:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:6:update_5:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:6:update_6:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:6:update_7:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:6:update_8:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:6:update_9:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_1:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_10:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_11:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_12:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_13:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_14:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_15:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_16:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_17:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_19:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_2:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_3:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_4:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_5:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_6:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_7:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_8:*:*:*:*:*:*
cpe:2.3:a:sun:jre:5.0:update_9:*:*:*:*:*:*
cpe:2.3:a:sun:jre:6:update_1:*:*:*:*:*:*
cpe:2.3:a:sun:jre:6:update_10:*:*:*:*:*:*
cpe:2.3:a:sun:jre:6:update_11:*:*:*:*:*:*
cpe:2.3:a:sun:jre:6:update_12:*:*:*:*:*:*
cpe:2.3:a:sun:jre:*:update_13:*:*:*:*:*:* versions up to 6 (inclusive)
cpe:2.3:a:sun:jre:6:update_2:*:*:*:*:*:*
cpe:2.3:a:sun:jre:6:update_3:*:*:*:*:*:*
cpe:2.3:a:sun:jre:6:update_4:*:*:*:*:*:*
cpe:2.3:a:sun:jre:6:update_5:*:*:*:*:*:*
cpe:2.3:a:sun:jre:6:update_6:*:*:*:*:*:*
cpe:2.3:a:sun:jre:6:update_7:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
107416 | Solaris 10 (sparc) : 125136-75 | Nessus | Solaris Local Security Checks | critical |
107415 | Solaris 10 (sparc) : 125136-71 | Nessus | Solaris Local Security Checks | critical |
89736 | VMware ESX Java Runtime Environment (JRE) Multiple Vulnerabilities (VMSA-2010-0002) (remote check) | Nessus | VMware ESX Local Security Checks | critical |
89117 | VMware ESX / ESXi Multiple Vulnerabilities (VMSA-2009-0016) (remote check) | Nessus | Misc. | critical |
67905 | Oracle Linux 5 : java-1.6.0-openjdk (ELSA-2009-1201) | Nessus | Oracle Linux Local Security Checks | critical |
64830 | Sun Java JRE Multiple Vulnerabilities (263408 / 263409 / 263428 ..) (Unix) | Nessus | Misc. | critical |
60645 | Scientific Linux Security Update : java (jdk 1.6.0) on SL4.x, SL5.x i386/x86_64 | Nessus | Scientific Linux Local Security Checks | critical |
60633 | Scientific Linux Security Update : java-1.6.0-openjdk on SL5.3 i386/x86_64 | Nessus | Scientific Linux Local Security Checks | critical |
53539 | RHEL 4 : Sun Java Runtime in Satellite Server (RHSA-2009:1662) | Nessus | Red Hat Local Security Checks | critical |
45386 | VMSA-2010-0002 : VMware vCenter update release addresses multiple security issues in Java JRE | Nessus | VMware ESX Local Security Checks | critical |
44029 | RHEL 4 / 5 : IBM Java Runtime in Satellite Server (RHSA-2010:0043) | Nessus | Red Hat Local Security Checks | critical |
43774 | CentOS 5 : java-1.6.0-openjdk (CESA-2009:1201) | Nessus | CentOS Local Security Checks | critical |
42870 | VMSA-2009-0016 : VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components. | Nessus | VMware ESX Local Security Checks | critical |
42834 | GLSA-200911-02 : Sun JDK/JRE: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | critical |
42790 | RHEL 4 / 5 : java-1.6.0-ibm (RHSA-2009:1582) | Nessus | Red Hat Local Security Checks | critical |
42396 | SuSE 11 Security Update : IBM Java 1.6.0 (SAT Patch Number 1497) | Nessus | SuSE Local Security Checks | critical |
42008 | openSUSE 10 Security Update : java-1_6_0-sun (java-1_6_0-sun-6395) | Nessus | SuSE Local Security Checks | critical |
42007 | openSUSE 10 Security Update : java-1_5_0-sun (java-1_5_0-sun-6396) | Nessus | SuSE Local Security Checks | critical |
41623 | openSUSE Security Update : java-1_6_0-openjdk (java-1_6_0-openjdk-1330) | Nessus | SuSE Local Security Checks | critical |
41622 | openSUSE Security Update : java-1_6_0-openjdk (java-1_6_0-openjdk-1330) | Nessus | SuSE Local Security Checks | critical |
41408 | SuSE 11 Security Update : Sun Java 1.6.0 (SAT Patch Number 1163) | Nessus | SuSE Local Security Checks | critical |
40873 | Mac OS X : Java for Mac OS X 10.5 Update 5 | Nessus | MacOS X Local Security Checks | high |
40814 | RHEL 4 / 5 : java-1.5.0-ibm (RHSA-2009:1236) | Nessus | Red Hat Local Security Checks | critical |
40749 | RHEL 4 / 5 : java-1.6.0-sun (RHSA-2009:1200) | Nessus | Red Hat Local Security Checks | critical |
40748 | RHEL 4 / 5 : java-1.5.0-sun (RHSA-2009:1199) | Nessus | Red Hat Local Security Checks | critical |
40547 | Ubuntu 8.10 / 9.04 : openjdk-6 vulnerabilities (USN-814-1) | Nessus | Ubuntu Local Security Checks | critical |
40527 | openSUSE Security Update : java-1_6_0-sun (java-1_6_0-sun-1161) | Nessus | SuSE Local Security Checks | critical |
40526 | openSUSE Security Update : java-1_5_0-sun (java-1_5_0-sun-1162) | Nessus | SuSE Local Security Checks | critical |
40525 | openSUSE Security Update : java-1_6_0-sun (java-1_6_0-sun-1161) | Nessus | SuSE Local Security Checks | critical |
40524 | openSUSE Security Update : java-1_5_0-sun (java-1_5_0-sun-1162) | Nessus | SuSE Local Security Checks | critical |
40515 | Fedora 10 : java-1.6.0-openjdk-1.6.0.0-20.b16.fc10 (2009-8337) | Nessus | Fedora Local Security Checks | critical |
40510 | RHEL 5 : java-1.6.0-openjdk (RHSA-2009:1201) | Nessus | Red Hat Local Security Checks | critical |
40507 | Fedora 11 : java-1.6.0-openjdk-1.6.0.0-27.b16.fc11 (2009-8329) | Nessus | Fedora Local Security Checks | critical |
40495 | Sun Java JRE Multiple Vulnerabilities (263408 / 263409 / 263428 ..) | Nessus | Windows | high |
27020 | Solaris 9 (sparc) : 125136-97 | Nessus | Solaris Local Security Checks | critical |
27008 | Solaris 8 (sparc) : 125136-97 | Nessus | Solaris Local Security Checks | critical |
26984 | Solaris 10 (sparc) : 125136-97 (deprecated) | Nessus | Solaris Local Security Checks | critical |