CVE Vulnerabilities

CVE-2008-5355

Improper Authentication

Published: Dec 05, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The Java Update feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
JdkSun*5.0 (including)
JdkSun*6 (including)
JdkSun5.0-update_1 (including)5.0-update_1 (including)
JdkSun5.0-update_10 (including)5.0-update_10 (including)
JdkSun5.0-update_11 (including)5.0-update_11 (including)
JdkSun5.0-update_12 (including)5.0-update_12 (including)
JdkSun5.0-update_13 (including)5.0-update_13 (including)
JdkSun5.0-update_14 (including)5.0-update_14 (including)
JdkSun5.0-update_15 (including)5.0-update_15 (including)
JdkSun5.0-update_2 (including)5.0-update_2 (including)
JdkSun5.0-update_3 (including)5.0-update_3 (including)
JdkSun5.0-update_4 (including)5.0-update_4 (including)
JdkSun5.0-update_5 (including)5.0-update_5 (including)
JdkSun5.0-update_6 (including)5.0-update_6 (including)
JdkSun5.0-update_7 (including)5.0-update_7 (including)
JdkSun5.0-update_8 (including)5.0-update_8 (including)
JdkSun5.0-update_9 (including)5.0-update_9 (including)
JdkSun6 (including)6 (including)
JdkSun6-update_1 (including)6-update_1 (including)
JdkSun6-update_2 (including)6-update_2 (including)
JdkSun6-update_3 (including)6-update_3 (including)
JdkSun6-update_4 (including)6-update_4 (including)
JdkSun6-update_5 (including)6-update_5 (including)
JdkSun6-update_6 (including)6-update_6 (including)
JdkSun6-update_7 (including)6-update_7 (including)
JdkSun6-update_8 (including)6-update_8 (including)
JdkSun6-update_9 (including)6-update_9 (including)
JreSun*1.4.2_18 (including)
JreSun*5.0 (including)
JreSun*6 (including)
JreSun1.4.2_1 (including)1.4.2_1 (including)
JreSun1.4.2_2 (including)1.4.2_2 (including)
JreSun1.4.2_3 (including)1.4.2_3 (including)
JreSun1.4.2_4 (including)1.4.2_4 (including)
JreSun1.4.2_5 (including)1.4.2_5 (including)
JreSun1.4.2_6 (including)1.4.2_6 (including)
JreSun1.4.2_7 (including)1.4.2_7 (including)
JreSun1.4.2_8 (including)1.4.2_8 (including)
JreSun1.4.2_9 (including)1.4.2_9 (including)
JreSun1.4.2_10 (including)1.4.2_10 (including)
JreSun1.4.2_11 (including)1.4.2_11 (including)
JreSun1.4.2_12 (including)1.4.2_12 (including)
JreSun1.4.2_13 (including)1.4.2_13 (including)
JreSun1.4.2_14 (including)1.4.2_14 (including)
JreSun1.4.2_15 (including)1.4.2_15 (including)
JreSun1.4.2_16 (including)1.4.2_16 (including)
JreSun1.4.2_17 (including)1.4.2_17 (including)
JreSun5.0 (including)5.0 (including)
JreSun5.0-update_1 (including)5.0-update_1 (including)
JreSun5.0-update_10 (including)5.0-update_10 (including)
JreSun5.0-update_11 (including)5.0-update_11 (including)
JreSun5.0-update_12 (including)5.0-update_12 (including)
JreSun5.0-update_13 (including)5.0-update_13 (including)
JreSun5.0-update_14 (including)5.0-update_14 (including)
JreSun5.0-update_15 (including)5.0-update_15 (including)
JreSun5.0-update_2 (including)5.0-update_2 (including)
JreSun5.0-update_3 (including)5.0-update_3 (including)
JreSun5.0-update_4 (including)5.0-update_4 (including)
JreSun5.0-update_5 (including)5.0-update_5 (including)
JreSun5.0-update_6 (including)5.0-update_6 (including)
JreSun5.0-update_7 (including)5.0-update_7 (including)
JreSun5.0-update_8 (including)5.0-update_8 (including)
JreSun5.0-update_9 (including)5.0-update_9 (including)
JreSun6 (including)6 (including)
JreSun6-update_1 (including)6-update_1 (including)
JreSun6-update_2 (including)6-update_2 (including)
JreSun6-update_3 (including)6-update_3 (including)
JreSun6-update_4 (including)6-update_4 (including)
JreSun6-update_5 (including)6-update_5 (including)
JreSun6-update_6 (including)6-update_6 (including)
JreSun6-update_7 (including)6-update_7 (including)
JreSun6-update_8 (including)6-update_8 (including)
JreSun6-update_9 (including)6-update_9 (including)
SdkSun*1.4.2_18 (including)
SdkSun1.4.2_1 (including)1.4.2_1 (including)
SdkSun1.4.2_2 (including)1.4.2_2 (including)
SdkSun1.4.2_3 (including)1.4.2_3 (including)
SdkSun1.4.2_4 (including)1.4.2_4 (including)
SdkSun1.4.2_5 (including)1.4.2_5 (including)
SdkSun1.4.2_6 (including)1.4.2_6 (including)
SdkSun1.4.2_7 (including)1.4.2_7 (including)
SdkSun1.4.2_8 (including)1.4.2_8 (including)
SdkSun1.4.2_9 (including)1.4.2_9 (including)
SdkSun1.4.2_10 (including)1.4.2_10 (including)
SdkSun1.4.2_11 (including)1.4.2_11 (including)
SdkSun1.4.2_12 (including)1.4.2_12 (including)
SdkSun1.4.2_13 (including)1.4.2_13 (including)
SdkSun1.4.2_14 (including)1.4.2_14 (including)
SdkSun1.4.2_15 (including)1.4.2_15 (including)
SdkSun1.4.2_16 (including)1.4.2_16 (including)
SdkSun1.4.2_17 (including)1.4.2_17 (including)

Potential Mitigations

References