vendor:
N/A
by:
Marc Schoenefeld
7.5
CVSS
HIGH
Isolation Violation
264
CWE
Product Name: N/A
Affected Version From: Java Plug-in 1.4.2_01
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows
2002
Java Applet Isolation Violation
A vulnerability has been reported in Java implementations that may potentially allow Java applets from two different domains to violate the sandbox security model and share read/write access to data areas. This violates the principle of isolation that should be enforced by Java and it is possible for unsigned applets to gain unauthorized access to data used by signed applets.
Mitigation:
Ensure that applets from different domains are not able to share data.