- Description
- Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3) AccessibleResourceBundle.getContents, (4) ImageReaderSpi.STANDARD_INPUT_TYPE, (5) ImageWriterSpi.STANDARD_OUTPUT_TYPE, (6) the imageio plugins, (7) DnsContext.debug, (8) RmfFileReader/StandardMidiFileWriter.types, (9) AbstractSaslImpl.logger, (10) Synth.Region.uiToRegionMap/lowerCaseNameMap, (11) the Introspector class and a cache of BeanInfo, and (12) JAX-WS, a different vulnerability than CVE-2009-2673.
- Source
- secalert@redhat.com
- NVD status
- Modified
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sun:java_se:*:20:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "625B941A-B638-46C2-A840-83724D5F826B",
"versionEndIncluding": "5.0"
},
{
"criteria": "cpe:2.3:a:sun:java_se:*:14:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB9DE8D5-D4F6-45DE-9DB4-9E5BB7E518F9",
"versionEndIncluding": "6"
},
{
"criteria": "cpe:2.3:a:sun:openjdk:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E78309B-E13F-4B65-9F59-39A993B900AF"
}
],
"operator": "OR"
}
]
}
]