Vulnerability Description
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka "three vulnerabilities."
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun | Jdk | 1.5.0 |
| Sun | Jre | 1.3.0 |
| Sun | Sdk | 1.3.1_01 |
Related Weaknesses (CWE)
References
- http://dev2dev.bea.com/pub/advisory/272
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01234533
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.html
- http://secunia.com/advisories/27206
- http://secunia.com/advisories/27261
- http://secunia.com/advisories/27693Patch
- http://secunia.com/advisories/27716Patch
- http://secunia.com/advisories/27804
- http://secunia.com/advisories/28777
- http://secunia.com/advisories/28880
- http://secunia.com/advisories/29042
- http://secunia.com/advisories/29858
- http://secunia.com/advisories/29897
- http://secunia.com/advisories/30676
- http://secunia.com/advisories/30780
FAQ
What is CVE-2007-5238?
CVE-2007-5238 is a vulnerability with a CVSS score of 2.6 (LOW). Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applic...
How severe is CVE-2007-5238?
CVE-2007-5238 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5238?
Check the references section above for vendor advisories and patch information. Affected products include: Sun Jdk, Sun Jre, Sun Sdk.