OpenJDK Applet Trusted Methods Chaining Privilege Escalation Vulnerability (6904691)
Published Apr 1, 2010 ·Due Jun 15, 2022
9.8
CRITICALCVSS 3.1
EPSS 96.32%
Description
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."
Affected products
No data.
Configuration 1
Configuration 2
Configuration 3
- 8.04
- 8.10
- 9.04
- 9.10
No data.
Extras for RHEL 3
java-1.4.2-ibm-0:1.4.2.13.5-1jpp.1.el3
Fixed · RHSA-2010:0574
Extras for RHEL 4
java-1.4.2-ibm-0:1.4.2.13.5-1jpp.1.el4
Fixed · RHSA-2010:0574
Extras for RHEL 4
java-1.5.0-ibm-1:1.5.0.11.2-1jpp.1.el4
Fixed · RHSA-2010:0489
Extras for RHEL 4
java-1.5.0-sun-0:1.5.0.22-1jpp.3.el4
Fixed · RHSA-2010:0338
Extras for RHEL 4
java-1.6.0-ibm-1:1.6.0.8-1jpp.1.el4
Fixed · RHSA-2010:0383
Extras for RHEL 4
java-1.6.0-sun-1:1.6.0.19-1jpp.1.el4
Fixed · RHSA-2010:0337
Extras for RHEL 4.7.z
java-1.5.0-sun-0:1.5.0.22-1jpp.3.el4
Fixed · RHSA-2010:0338
RHEL 4 for SAP
java-1.4.2-ibm-sap-0:1.4.2.13.5.sap-1jpp.1.el4_8
Fixed · RHSA-2010:0586
RHEL 5 for SAP
java-1.4.2-ibm-sap-0:1.4.2.13.5.sap-1jpp.1.el5
Fixed · RHSA-2010:0586
Red Hat Enterprise Linux 5
java-1.6.0-openjdk-1:1.6.0.0-1.11.b16.el5
Fixed · RHSA-2010:0339
Red Hat Network Satellite Server v 5.3
java-1.6.0-ibm-1:1.6.0.8-1jpp.1.el4
Fixed · RHSA-2010:0471
Supplementary for RHEL 5.2.z
java-1.5.0-sun-0:1.5.0.22-1jpp.3.el5
Fixed · RHSA-2010:0338
Supplementary for RHEL 5.3.z
java-1.5.0-sun-0:1.5.0.22-1jpp.3.el5
Fixed · RHSA-2010:0338
Supplementary for Red Hat Enterprise Linux 5
java-1.4.2-ibm-0:1.4.2.13.5-1jpp.1.el5
Fixed · RHSA-2010:0574
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-ibm-1:1.5.0.11.2-1jpp.1.el5
Fixed · RHSA-2010:0489
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-sun-0:1.5.0.22-1jpp.3.el5
Fixed · RHSA-2010:0338
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-ibm-1:1.6.0.8-1jpp.1.el5
Fixed · RHSA-2010:0383
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.19-1jpp.1.el5
Fixed · RHSA-2010:0337
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 3 | java-1.4.2-ibm-0:1.4.2.13.5-1jpp.1.el3 | Fixed | RHSA-2010:0574 |
| Extras for RHEL 4 | java-1.4.2-ibm-0:1.4.2.13.5-1jpp.1.el4 | Fixed | RHSA-2010:0574 |
| Extras for RHEL 4 | java-1.5.0-ibm-1:1.5.0.11.2-1jpp.1.el4 | Fixed | RHSA-2010:0489 |
| Extras for RHEL 4 | java-1.5.0-sun-0:1.5.0.22-1jpp.3.el4 | Fixed | RHSA-2010:0338 |
| Extras for RHEL 4 | java-1.6.0-ibm-1:1.6.0.8-1jpp.1.el4 | Fixed | RHSA-2010:0383 |
| Extras for RHEL 4 | java-1.6.0-sun-1:1.6.0.19-1jpp.1.el4 | Fixed | RHSA-2010:0337 |
| Extras for RHEL 4.7.z | java-1.5.0-sun-0:1.5.0.22-1jpp.3.el4 | Fixed | RHSA-2010:0338 |
| RHEL 4 for SAP | java-1.4.2-ibm-sap-0:1.4.2.13.5.sap-1jpp.1.el4_8 | Fixed | RHSA-2010:0586 |
| RHEL 5 for SAP | java-1.4.2-ibm-sap-0:1.4.2.13.5.sap-1jpp.1.el5 | Fixed | RHSA-2010:0586 |
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk-1:1.6.0.0-1.11.b16.el5 | Fixed | RHSA-2010:0339 |
| Red Hat Network Satellite Server v 5.3 | java-1.6.0-ibm-1:1.6.0.8-1jpp.1.el4 | Fixed | RHSA-2010:0471 |
| Supplementary for RHEL 5.2.z | java-1.5.0-sun-0:1.5.0.22-1jpp.3.el5 | Fixed | RHSA-2010:0338 |
| Supplementary for RHEL 5.3.z | java-1.5.0-sun-0:1.5.0.22-1jpp.3.el5 | Fixed | RHSA-2010:0338 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.4.2-ibm-0:1.4.2.13.5-1jpp.1.el5 | Fixed | RHSA-2010:0574 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-ibm-1:1.5.0.11.2-1jpp.1.el5 | Fixed | RHSA-2010:0489 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-sun-0:1.5.0.22-1jpp.3.el5 | Fixed | RHSA-2010:0338 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-ibm-1:1.6.0.8-1jpp.1.el5 | Fixed | RHSA-2010:0383 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.19-1jpp.1.el5 | Fixed | RHSA-2010:0337 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Date Added
May 25, 2022
Patch Due
Jun 15, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Feb 10, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 96.32% (0.96319) | 99.88th | v5 (v2026.06.15) |
| Jun 15, 2026 | 96.17% (0.96166) | 99.87th | v5 (v2026.06.15) |
| Mar 17, 2025 | 92.19% (0.92190) | 99.71th | v4 (v2025.03.14) |
| Dec 17, 2024 | 93.63% (0.93627) | 99.32th | v3 (v2023.03.01) |
| Jul 4, 2024 | 94.77% (0.94769) | 99.29th | v3 (v2023.03.01) |
| Jun 29, 2024 | 93.50% (0.93503) | 99.12th | v3 (v2023.03.01) |
| Oct 11, 2023 | 94.41% (0.94408) | 98.94th | v3 (v2023.03.01) |
| Mar 7, 2023 | 93.90% (0.93900) | 98.58th | v3 (v2023.03.01) |
| Mar 6, 2023 | 83.98% (0.83982) | 99.62th | v2 (v2022.01.01) |
| Feb 4, 2022 | 83.98% (0.83982) | 99.55th | v2 (v2022.01.01) |
No CWE recorded.
References (46)
- http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751 vendor-advisoryx_refsource_HPBroken Link
- http://lists.apple.com/archives/security-announce/2010//May/msg00001.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://lists.apple.com/archives/security-announce/2010//May/msg00002.html vendor-advisoryx_refsource_APPLEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=127557596201693&w=2 vendor-advisoryx_refsource_HPMailing List
- http://marc.info/?l=bugtraq&m=134254866602253&w=2 vendor-advisoryx_refsource_HPMailing List
- http://secunia.com/advisories/39292 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/39317 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/39659 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/39819 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/40211 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/40545 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/43308 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://support.apple.com/kb/HT4170 x_refsource_CONFIRMRelease NotesThird Party Advisory
- http://support.apple.com/kb/HT4171 x_refsource_CONFIRMRelease NotesThird Party Advisory
- http://ubuntu.com/usn/usn-923-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:084 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html x_refsource_CONFIRMPatchThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html x_refsource_CONFIRMPatchThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2010-0337.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0338.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0339.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0383.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0471.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0489.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/archive/1/510528/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/516397/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/39065 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html x_refsource_CONFIRMThird Party Advisory
- http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html x_refsource_CONFIRMRelease Notes
- http://www.vupen.com/english/advisories/2010/1107 vdb-entryx_refsource_VUPENBroken Link
- http://www.vupen.com/english/advisories/2010/1191 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2010/1454 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2010/1523 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2010/1793 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-10-056 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2010-0840 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=575846 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-0840
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13971 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9974 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0840 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2010-0840
Change history (0)
No recorded changes yet.