Vulnerability Description
The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Mac Os Runtime For Java | <= 2.1 |
References
- http://archives.neohapsis.com/archives/bugtraq/2000-06/0056.htmlExploitPatchVendor Advisory
- http://www.securityfocus.com/bid/1336
- http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-05-8&msg=39
- http://archives.neohapsis.com/archives/bugtraq/2000-06/0056.htmlExploitPatchVendor Advisory
- http://www.securityfocus.com/bid/1336
- http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-05-8&msg=39
FAQ
What is CVE-2000-0563?
CVE-2000-0563 is a vulnerability with a CVSS score of 10.0 (HIGH). The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP ...
How severe is CVE-2000-0563?
CVE-2000-0563 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-0563?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os Runtime For Java.