VDB
CVE-2009-2690
CVE-2009-2690
PUBLISHED
CVSS 5 MEDIUM
The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-dependent attackers to obtain sensitive information via an untrusted (1) applet or (2) application.
EPSS 4.37% · 89.2th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
4.37%
89.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| sun | java_se | 0 |
| sun | openjdk | |
| n/a | n/a | * |
Exploit Intelligence
- RHSA-2009:1200 (circl)
- 36162 (circl)
- ADV-2009-2543 (circl)
- GLSA-200911-02 (circl)
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1 (circl)
- oval:org.mitre.oval:def:9443 (circl)
- https://bugzilla.redhat.com/show_bug.cgi?id=513223 (circl)
- MDVSA-2009:209 (circl)
- FEDORA-2009-8329 (circl)
- http://java.sun.com/javase/6/webnotes/6u15.html (circl)
…and 7 more exploits
Timeline
- Aug 10, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- RHSA-2009:1200 vendor-advisory
- 36162 third-party-advisory
- ADV-2009-2543 vdb
- GLSA-200911-02 vendor-advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1 url
- oval:org.mitre.oval:def:9443 vdb
- https://bugzilla.redhat.com/show_bug.cgi?id=513223 url
- MDVSA-2009:209 vendor-advisory
- FEDORA-2009-8329 vendor-advisory
- http://java.sun.com/javase/6/webnotes/6u15.html url
- 36180 third-party-advisory
- 36176 third-party-advisory
- FEDORA-2009-8337 vendor-advisory
- SUSE-SR:2009:016 vendor-advisory
- APPLE-SA-2009-09-03-1 vendor-advisory
- RHSA-2009:1201 vendor-advisory
- 37386 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-2690 advisory