CVE Vulnerabilities

CVE-2009-2672

Published: Aug 05, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
4.3 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
JdkSun*6 (including)
JdkSun5.0-update_1 (including)5.0-update_1 (including)
JdkSun5.0-update_10 (including)5.0-update_10 (including)
JdkSun5.0-update_11 (including)5.0-update_11 (including)
JdkSun5.0-update_12 (including)5.0-update_12 (including)
JdkSun5.0-update_13 (including)5.0-update_13 (including)
JdkSun5.0-update_14 (including)5.0-update_14 (including)
JdkSun5.0-update_15 (including)5.0-update_15 (including)
JdkSun5.0-update_16 (including)5.0-update_16 (including)
JdkSun5.0-update_17 (including)5.0-update_17 (including)
JdkSun5.0-update_2 (including)5.0-update_2 (including)
JdkSun5.0-update_3 (including)5.0-update_3 (including)
JdkSun5.0-update_4 (including)5.0-update_4 (including)
JdkSun5.0-update_5 (including)5.0-update_5 (including)
JdkSun5.0-update_6 (including)5.0-update_6 (including)
JdkSun5.0-update_7 (including)5.0-update_7 (including)
JdkSun5.0-update_8 (including)5.0-update_8 (including)
JdkSun5.0-update_9 (including)5.0-update_9 (including)
JdkSun6-update_1 (including)6-update_1 (including)
JdkSun6-update_10 (including)6-update_10 (including)
JdkSun6-update_11 (including)6-update_11 (including)
JdkSun6-update_12 (including)6-update_12 (including)
JdkSun6-update_2 (including)6-update_2 (including)
JdkSun6-update_3 (including)6-update_3 (including)
JdkSun6-update_4 (including)6-update_4 (including)
JdkSun6-update_5 (including)6-update_5 (including)
JdkSun6-update_6 (including)6-update_6 (including)
JdkSun6-update_7 (including)6-update_7 (including)
JdkSun6-update_8 (including)6-update_8 (including)
JdkSun6-update_9 (including)6-update_9 (including)
JreSun*6 (including)
JreSun5.0-update_1 (including)5.0-update_1 (including)
JreSun5.0-update_10 (including)5.0-update_10 (including)
JreSun5.0-update_11 (including)5.0-update_11 (including)
JreSun5.0-update_12 (including)5.0-update_12 (including)
JreSun5.0-update_13 (including)5.0-update_13 (including)
JreSun5.0-update_14 (including)5.0-update_14 (including)
JreSun5.0-update_15 (including)5.0-update_15 (including)
JreSun5.0-update_16 (including)5.0-update_16 (including)
JreSun5.0-update_17 (including)5.0-update_17 (including)
JreSun5.0-update_19 (including)5.0-update_19 (including)
JreSun5.0-update_2 (including)5.0-update_2 (including)
JreSun5.0-update_3 (including)5.0-update_3 (including)
JreSun5.0-update_4 (including)5.0-update_4 (including)
JreSun5.0-update_5 (including)5.0-update_5 (including)
JreSun5.0-update_6 (including)5.0-update_6 (including)
JreSun5.0-update_7 (including)5.0-update_7 (including)
JreSun5.0-update_8 (including)5.0-update_8 (including)
JreSun5.0-update_9 (including)5.0-update_9 (including)
JreSun6-update_1 (including)6-update_1 (including)
JreSun6-update_10 (including)6-update_10 (including)
JreSun6-update_11 (including)6-update_11 (including)
JreSun6-update_12 (including)6-update_12 (including)
JreSun6-update_2 (including)6-update_2 (including)
JreSun6-update_3 (including)6-update_3 (including)
JreSun6-update_4 (including)6-update_4 (including)
JreSun6-update_5 (including)6-update_5 (including)
JreSun6-update_6 (including)6-update_6 (including)
JreSun6-update_7 (including)6-update_7 (including)
JreSun6-update_8 (including)6-update_8 (including)
JreSun6-update_9 (including)6-update_9 (including)
Extras for RHEL 4RedHatjava-1.5.0-sun-0:1.5.0.20-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.6.0-sun-1:1.6.0.15-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.5.0-ibm-1:1.5.0.10-1jpp.4.el4*
Extras for RHEL 4RedHatjava-1.6.0-ibm-1:1.6.0.6-1jpp.3.el4*
Red Hat Enterprise Linux 5RedHatjava-1.6.0-openjdk-1:1.6.0.0-1.2.b09.el5*
Red Hat Network Satellite Server v 5.1RedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.1.el4*
Red Hat Network Satellite Server v 5.3RedHatjava-1.6.0-ibm-1:1.6.0.7-1jpp.3.el4*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-sun-0:1.5.0.20-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-sun-1:1.6.0.15-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-ibm-1:1.5.0.10-1jpp.4.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-ibm-1:1.6.0.6-1jpp.3.el5*
Openjdk-6Ubuntuhardy*
Openjdk-6Ubuntuintrepid*
Openjdk-6Ubuntujaunty*
Openjdk-6Ubuntuupstream*
Sun-java5Ubuntudapper*
Sun-java5Ubuntugutsy*
Sun-java5Ubuntuintrepid*
Sun-java5Ubuntujaunty*
Sun-java5Ubuntuupstream*
Sun-java6Ubuntuhardy*
Sun-java6Ubuntuintrepid*
Sun-java6Ubuntujaunty*
Sun-java6Ubuntukarmic*
Sun-java6Ubuntulucid*
Sun-java6Ubuntuupstream*

References