CVE Vulnerabilities

CVE-2010-0840

Published: Apr 01, 2010 | Modified: Oct 22, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
7.5 CRITICAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) a similar trust issue with interfaces, aka Trusted Methods Chaining Remote Code Execution Vulnerability.

Affected Software

NameVendorStart VersionEnd Version
JreOracle1.4.2_25 (including)1.4.2_25 (including)
JreOracle1.5.0-update23 (including)1.5.0-update23 (including)
JreOracle1.6.0-update18 (including)1.6.0-update18 (including)
Extras for RHEL 3RedHatjava-1.4.2-ibm-0:1.4.2.13.5-1jpp.1.el3*
Extras for RHEL 4RedHatjava-1.6.0-sun-1:1.6.0.19-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.3.el4*
Extras for RHEL 4RedHatjava-1.6.0-ibm-1:1.6.0.8-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.5.0-ibm-1:1.5.0.11.2-1jpp.1.el4*
Extras for RHEL 4RedHatjava-1.4.2-ibm-0:1.4.2.13.5-1jpp.1.el4*
Extras for RHEL 4.7.zRedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.3.el4*
Red Hat Enterprise Linux 5RedHatjava-1.6.0-openjdk-1:1.6.0.0-1.11.b16.el5*
Red Hat Network Satellite Server v 5.3RedHatjava-1.6.0-ibm-1:1.6.0.8-1jpp.1.el4*
RHEL 4 for SAPRedHatjava-1.4.2-ibm-sap-0:1.4.2.13.5.sap-1jpp.1.el4_8*
RHEL 5 for SAPRedHatjava-1.4.2-ibm-sap-0:1.4.2.13.5.sap-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-sun-1:1.6.0.19-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.3.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-ibm-1:1.6.0.8-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-ibm-1:1.5.0.11.2-1jpp.1.el5*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.4.2-ibm-0:1.4.2.13.5-1jpp.1.el5*
Supplementary for RHEL 5.2.zRedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.3.el5*
Supplementary for RHEL 5.3.zRedHatjava-1.5.0-sun-0:1.5.0.22-1jpp.3.el5*
Openjdk-6Ubuntuhardy*
Openjdk-6Ubuntuintrepid*
Openjdk-6Ubuntujaunty*
Openjdk-6Ubuntukarmic*
Sun-java5Ubuntudapper*
Sun-java5Ubuntuhardy*
Sun-java5Ubuntuintrepid*
Sun-java5Ubuntujaunty*
Sun-java5Ubuntuupstream*
Sun-java6Ubuntuhardy*
Sun-java6Ubuntuintrepid*
Sun-java6Ubuntujaunty*
Sun-java6Ubuntukarmic*
Sun-java6Ubuntuupstream*

References