CVE-2009-2670
Last modified
CVE-2009-2670 is a vulnerability of currently unknown severity. The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties.. EPSS estimates a 3.29% chance of exploitation in the next 30 days.
Description
The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Sun | Jdk | <= 6 | Update 13 |
| Sun | Jdk | 5.0 | Update 1 |
| Sun | Jdk | 6 | Update 1 |
| Sun | Jre | <= 6 | Update 13 |
| Sun | Jre | 5.0 | Update 1 |
| Sun | Jre | 6 | Update 1 |
References
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-263408-1Patch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-294A.htmlUS Government Resource
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-263408-1Patch, Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-294A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-2670?
How severe is CVE-2009-2670?
How do I fix CVE-2009-2670?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-2664The js_watch_set function in js/src/jsdbgapi.cpp in the Java…
- CVE-2009-2665The nsDocument::SetScriptGlobalObject function in content/ba…
- CVE-2009-2666socket.c in fetchmail before 6.3.11 does not properly handle…
- CVE-2009-2667Unspecified vulnerability in IBM Tivoli Key Lifecycle Manage…
- CVE-2009-2668Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 th…
- CVE-2009-2669A certain debugging component in IBM AIX 5.3 and 6.1 does no…
- CVE-2009-2671The SOCKS proxy implementation in Sun Java Runtime Environme…
- CVE-2009-2672The proxy mechanism implementation in Sun Java Runtime Envir…
- CVE-2009-2673The proxy mechanism implementation in Sun Java Runtime Envir…
- CVE-2009-2674Integer overflow in javaws.exe in Sun Java Web Start in Sun …
- CVE-2009-2675Integer overflow in the unpack200 utility in Sun Java Runtim…
- CVE-2009-2676Unspecified vulnerability in JNLPAppletlauncher in Sun Java …
Are you affected by CVE-2009-2670?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
