vendor:
Java Runtime Environment
by:
Sami Koivu, Matthias Kaiser, egypt
N/A
CVSS
N/A
Java Runtime Environment vulnerability
264
CWE
Product Name: Java Runtime Environment
Affected Version From: 6 prior to update 19 and version 5 prior to update 23.
Affected Version To: 6 prior to update 19 and version 5 prior to update 23.
Patch Exists: YES
Related CWE: CVE-2010-0840
CPE: a:oracle:java_runtime_environment
Metasploit:
https://www.rapid7.com/db/vulnerabilities/apple-java-cve-2010-0840/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0471/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2010-0840/, https://www.rapid7.com/db/vulnerabilities/vmsa-2011-0003-cve-2010-0840/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0337/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0338/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0574/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0586/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2010-0840/, https://www.rapid7.com/db/vulnerabilities/jre-unspecified-cve-2010-0840/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2010-0840/, https://www.rapid7.com/db/vulnerabilities/hpsim-cve-2010-0840/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0339/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0383/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0489/
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=49862, https://www.infosecmatter.com/nessus-plugin-library/?id=45465, https://www.infosecmatter.com/nessus-plugin-library/?id=64842, https://www.infosecmatter.com/nessus-plugin-library/?id=45379, https://www.infosecmatter.com/nessus-plugin-library/?id=47617, https://www.infosecmatter.com/nessus-plugin-library/?id=46674, https://www.infosecmatter.com/nessus-plugin-library/?id=89674, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/browser/java_trusted_chain, https://www.infosecmatter.com/nessus-plugin-library/?id=57619, https://www.infosecmatter.com/list-of-metasploit-linux-exploits-detailed-spreadsheet/
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2010
Java Statement.invoke() Trusted Method Chain Exploit
This module exploits a vulnerability in Java Runtime Environment that allows an untrusted method to run in a privileged context. The vulnerability affects version 6 prior to update 19 and version 5 prior to update 23.
Mitigation:
Update Java Runtime Environment to version 6 update 19 and version 5 update 23.