← Back

CVE-2009-2672

nvd nist
Published: Aug 5, 2009Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.

Affected (61)

Products: Sun: Jdk, Jre
2 products
Jdk
Jre
Configuration A
61 vulnerable
Vulnerable SoftwareAffected Versions
Sun
Up to 6
Version 5.0 update_10
Version 5.0 update_11
Version 5.0 update_12
Version 5.0 update_13
Version 5.0 update_14
Version 5.0 update_15
Version 5.0 update_16
Version 5.0 update_17
Version 5.0 update_1
Version 5.0 update_2
Version 5.0 update_3
Version 5.0 update_4
Version 5.0 update_5
Version 5.0 update_6
Version 5.0 update_7
Version 5.0 update_8
Version 5.0 update_9
Version 6 update_10
Version 6 update_11
Version 6 update_12
Version 6 update_1
Version 6 update_2
Version 6 update_3
Version 6 update_4
Version 6 update_5
Version 6 update_6
Version 6 update_7
Version 6 update_8
Version 6 update_9
Sun
Up to 6
Version 5.0 update_10
Version 5.0 update_11
Version 5.0 update_12
Version 5.0 update_13
Version 5.0 update_14
Version 5.0 update_15
Version 5.0 update_16
Version 5.0 update_17
Version 5.0 update_19
Version 5.0 update_1
Version 5.0 update_2
Version 5.0 update_3
Version 5.0 update_4
Version 5.0 update_5
Version 5.0 update_6
Version 5.0 update_7
Version 5.0 update_8
Version 5.0 update_9
Version 6 update_10
Version 6 update_11
Version 6 update_12
Version 6 update_1
Version 6 update_2
Version 6 update_3
Version 6 update_4
Version 6 update_5
Version 6 update_6
Version 6 update_7
Version 6 update_8
Version 6 update_9

Related CWEs

References (62)

Source: cve@mitre.org
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.