CVE Vulnerabilities

CVE-2010-0840

Published: Apr 01, 2010 | Modified: Jun 28, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
7.5 CRITICAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) a similar trust issue with interfaces, aka Trusted Methods Chaining Remote Code Execution Vulnerability.

Affected Software

Name Vendor Start Version End Version
Jre Oracle 1.4.2_25 (including) 1.4.2_25 (including)
Jre Oracle 1.5.0-update23 (including) 1.5.0-update23 (including)
Jre Oracle 1.6.0-update18 (including) 1.6.0-update18 (including)
Extras for RHEL 3 RedHat java-1.4.2-ibm-0:1.4.2.13.5-1jpp.1.el3 *
Extras for RHEL 4 RedHat java-1.6.0-sun-1:1.6.0.19-1jpp.1.el4 *
Extras for RHEL 4 RedHat java-1.5.0-sun-0:1.5.0.22-1jpp.3.el4 *
Extras for RHEL 4 RedHat java-1.6.0-ibm-1:1.6.0.8-1jpp.1.el4 *
Extras for RHEL 4 RedHat java-1.5.0-ibm-1:1.5.0.11.2-1jpp.1.el4 *
Extras for RHEL 4 RedHat java-1.4.2-ibm-0:1.4.2.13.5-1jpp.1.el4 *
Extras for RHEL 4.7.z RedHat java-1.5.0-sun-0:1.5.0.22-1jpp.3.el4 *
Red Hat Enterprise Linux 5 RedHat java-1.6.0-openjdk-1:1.6.0.0-1.11.b16.el5 *
Red Hat Network Satellite Server v 5.3 RedHat java-1.6.0-ibm-1:1.6.0.8-1jpp.1.el4 *
RHEL 4 for SAP RedHat java-1.4.2-ibm-sap-0:1.4.2.13.5.sap-1jpp.1.el4_8 *
RHEL 5 for SAP RedHat java-1.4.2-ibm-sap-0:1.4.2.13.5.sap-1jpp.1.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.6.0-sun-1:1.6.0.19-1jpp.1.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.5.0-sun-0:1.5.0.22-1jpp.3.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.6.0-ibm-1:1.6.0.8-1jpp.1.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.5.0-ibm-1:1.5.0.11.2-1jpp.1.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.4.2-ibm-0:1.4.2.13.5-1jpp.1.el5 *
Supplementary for RHEL 5.2.z RedHat java-1.5.0-sun-0:1.5.0.22-1jpp.3.el5 *
Supplementary for RHEL 5.3.z RedHat java-1.5.0-sun-0:1.5.0.22-1jpp.3.el5 *
Openjdk-6 Ubuntu hardy *
Openjdk-6 Ubuntu intrepid *
Openjdk-6 Ubuntu jaunty *
Openjdk-6 Ubuntu karmic *
Sun-java5 Ubuntu dapper *
Sun-java5 Ubuntu hardy *
Sun-java5 Ubuntu intrepid *
Sun-java5 Ubuntu jaunty *
Sun-java5 Ubuntu upstream *
Sun-java6 Ubuntu hardy *
Sun-java6 Ubuntu intrepid *
Sun-java6 Ubuntu jaunty *
Sun-java6 Ubuntu karmic *
Sun-java6 Ubuntu upstream *

References