CVE-2009-3864
Last modified
CVE-2009-3864 is a vulnerability of currently unknown severity. The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694.. EPSS estimates a 22.48% chance of exploitation in the next 30 days.
Description
The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Windows | All versions | — |
| Sun | Jdk | 1.5.0 | Update1 |
| Sun | Jdk | 1.6.0 | Update1 |
| Sun | Jre | 1.5.0 | Update1 |
| Sun | Jre | 1.6.0 | Update 1 |
References
- http://secunia.com/advisories/37231Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-269868-1Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3131Patch, Vendor Advisory
- http://secunia.com/advisories/37231Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-269868-1Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3131Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-3864?
How severe is CVE-2009-3864?
How do I fix CVE-2009-3864?
Are you affected by CVE-2009-3864?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
