CVE-2009-3886
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/11/2009
Last modified:
09/04/2025
Description
The Java Web Start implementation in Sun Java SE 6 before Update 17 does not properly handle the interaction between a signed JAR file and a JNLP (1) application or (2) applet, which has unspecified impact and attack vectors, related to a "regression," aka Bug Id 6870531.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sun:jre:*:update_16:*:*:*:*:*:* | 1.6.0 (including) | |
| cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:jre:1.6.0:update_12:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:jre:1.6.0:update_13:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:jre:1.6.0:update_14:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:jre:1.6.0:update_15:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:jre:1.6.0:update_2:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:jre:1.6.0:update_3:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:jre:1.6.0:update_4:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:jre:1.6.0:update_5:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:jre:1.6.0:update_6:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:jre:1.6.0:update_7:*:*:*:*:*:* | ||
| cpe:2.3:a:sun:jre:1.6.0:update_8:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://java.sun.com/javase/6/webnotes/6u17.html
- http://secunia.com/advisories/37386
- http://security.gentoo.org/glsa/glsa-200911-02.xml
- https://bugzilla.redhat.com/show_bug.cgi?id=532914
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6794
- http://java.sun.com/javase/6/webnotes/6u17.html
- http://secunia.com/advisories/37386
- http://security.gentoo.org/glsa/glsa-200911-02.xml
- https://bugzilla.redhat.com/show_bug.cgi?id=532914
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6794



