Executive Summary

Informations
NameCVE-2007-5689First vendor Publication2007-10-29
VendorCveLast vendor Modification2011-03-07

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score10Attack RangeNetwork
Cvss Impact Score10Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Security Protection

ImpactsProvides administrator access : Allows complete confidentiality, integrity, and availability violation; Allows unauthorized disclosure of information; Allows disruption of service.

Detail

The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5689

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:9898
 
Oval ID: oval:org.mitre.oval:def:9898
Title: The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.
Description: The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary programs, or read or modify arbitrary files, via applets that grant privileges to themselves.
Family: unix Class: vulnerability
Reference(s): CVE-2007-5689
Version: 3
Platform(s): Red Hat Enterprise Linux Extras 4
Red Hat Enterprise Linux Extras 5
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application13
Application35
Application16

Open Source Vulnerability Database (OSVDB)

idDescription
40834Sun Java JDK / JRE Java Virtual Machine (JVM) Unspecified Applet Privilege Es...

Internal Sources (Detail)

SourceUrl
BEAhttp://dev2dev.bea.com/pub/advisory/272
BIDhttp://www.securityfocus.com/bid/26185
CONFIRMhttp://support.avaya.com/elmodocs2/security/ASA-2007-480.htm
http://www.vmware.com/security/advisories/VMSA-2008-0010.html
GENTOOhttp://security.gentoo.org/glsa/glsa-200804-28.xml
http://www.gentoo.org/security/en/glsa/glsa-200804-20.xml
http://www.gentoo.org/security/en/glsa/glsa-200806-11.xml
HPhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533
OSVDBhttp://osvdb.org/40834
SECTRACKhttp://www.securitytracker.com/id?1018847
SECUNIAhttp://secunia.com/advisories/27320
http://secunia.com/advisories/27693
http://secunia.com/advisories/29042
http://secunia.com/advisories/29858
http://secunia.com/advisories/30676
http://secunia.com/advisories/30780
SUNALERThttp://sunsolve.sun.com/search/document.do?assetkey=1-26-103112-1
VUPENhttp://www.vupen.com/english/advisories/2007/3589
http://www.vupen.com/english/advisories/2007/3895
http://www.vupen.com/english/advisories/2008/0609
http://www.vupen.com/english/advisories/2008/1856/references

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2013-05-11 10:40:41
  • Multiple Updates