Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-2086


Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3) user.home System Properties, aka "Java Web Start File Inclusion" and CR 6694892.


Published

2008-12-05T02:30:00.190

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 9.3 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sun jdk ≤ 5.0 Yes
Application sun jdk ≤ 6 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 5.0 Yes
Application sun jdk 6 Yes
Application sun jdk 6 Yes
Application sun jdk 6 Yes
Application sun jdk 6 Yes
Application sun jdk 6 Yes
Application sun jdk 6 Yes
Application sun jdk 6 Yes
Application sun jdk 6 Yes
Application sun jdk 6 Yes
Application sun jdk 6 Yes
Application sun jre ≤ 1.4.2_18 Yes
Application sun jre ≤ 5.0 Yes
Application sun jre ≤ 6 Yes
Application sun jre 1.4.2_1 Yes
Application sun jre 1.4.2_2 Yes
Application sun jre 1.4.2_3 Yes
Application sun jre 1.4.2_4 Yes
Application sun jre 1.4.2_5 Yes
Application sun jre 1.4.2_6 Yes
Application sun jre 1.4.2_7 Yes
Application sun jre 1.4.2_8 Yes
Application sun jre 1.4.2_9 Yes
Application sun jre 1.4.2_10 Yes
Application sun jre 1.4.2_11 Yes
Application sun jre 1.4.2_12 Yes
Application sun jre 1.4.2_13 Yes
Application sun jre 1.4.2_14 Yes
Application sun jre 1.4.2_15 Yes
Application sun jre 1.4.2_16 Yes
Application sun jre 1.4.2_17 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 5.0 Yes
Application sun jre 6 Yes
Application sun jre 6 Yes
Application sun jre 6 Yes
Application sun jre 6 Yes
Application sun jre 6 Yes
Application sun jre 6 Yes
Application sun jre 6 Yes
Application sun jre 6 Yes
Application sun jre 6 Yes
Application sun jre 6 Yes
Application sun sdk ≤ 1.4.2_18 Yes
Application sun sdk 1.4.2_1 Yes
Application sun sdk 1.4.2_2 Yes
Application sun sdk 1.4.2_3 Yes
Application sun sdk 1.4.2_4 Yes
Application sun sdk 1.4.2_5 Yes
Application sun sdk 1.4.2_6 Yes
Application sun sdk 1.4.2_7 Yes
Application sun sdk 1.4.2_8 Yes
Application sun sdk 1.4.2_9 Yes
Application sun sdk 1.4.2_10 Yes
Application sun sdk 1.4.2_11 Yes
Application sun sdk 1.4.2_12 Yes
Application sun sdk 1.4.2_13 Yes
Application sun sdk 1.4.2_14 Yes
Application sun sdk 1.4.2_15 Yes
Application sun sdk 1.4.2_16 Yes
Application sun sdk 1.4.2_17 Yes

References