Back

HIGH

OpenJDK Deserialization of RMIConnectionImpl objects should enforce stricter checks (6893947)

Published Apr 1, 2010

Description

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (40)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner oracle
Published Apr 1, 2010
Updated Aug 7, 2024
Reserved Dec 16, 2009

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 16, 2026

Red Hat

Severity Important
Public date Mar 30, 2010
Bugzilla 575769

ENISA EUVD

Assigner oracle
Published Apr 1, 2010
Updated Aug 7, 2024

GitHub

No data