CVE-2009-2689

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
10/08/2009
Last modified:
19/09/2017

Description

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sun:java_se:*:20:*:*:*:*:*:* 5.0 (including)
cpe:2.3:a:sun:java_se:*:14:*:*:*:*:*:* 6 (including)
cpe:2.3:a:sun:openjdk:*:*:*:*:*:*:*:*