Back

HIGH

Java Web Start, arbitrary file creation (6703909)

Published Jul 9, 2008

Description

Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create arbitrary files via the writeManifest method in the CacheEntry class, aka CR 6703909.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (45)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 9, 2008
Updated Aug 7, 2024
Reserved Jul 9, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Jul 8, 2008