CVE-2010-3860
Last modified
CVE-2010-3860 is a vulnerability of currently unknown severity. IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to obtain sensitive information including (1) user.name, (2) user.home, and (3) java.home system properties, and other sensitive information such as installation directories.. EPSS estimates a 3.00% chance of exploitation in the next 30 days.
Description
IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to obtain sensitive information including (1) user.name, (2) user.home, and (3) java.home system properties, and other sensitive information such as installation directories.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Redhat | Icedtea | <= 1.9.1 | — |
| Redhat | Icedtea | 1.5 | Rc1 |
| Redhat | Icedtea | 1.6 | — |
| Redhat | Icedtea | 1.7 | — |
| Redhat | Icedtea | 1.8 | — |
| Redhat | Icedtea | 1.8.1 | — |
| Redhat | Icedtea | 1.8.2 | — |
| Redhat | Icedtea | 1.9 | — |
References
- http://secunia.com/advisories/42412Vendor Advisory
- http://secunia.com/advisories/42417Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3090Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3108Vendor Advisory
- http://secunia.com/advisories/42412Vendor Advisory
- http://secunia.com/advisories/42417Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3090Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3108Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3860?
How severe is CVE-2010-3860?
How do I fix CVE-2010-3860?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-3854Multiple cross-site scripting (XSS) vulnerabilities in the w…
- CVE-2010-3855Buffer overflow in the ft_var_readpackedpoints function in t…
- CVE-2010-3856ld.so in the GNU C Library (aka glibc or libc6) before 2.11.…
- CVE-2010-3857JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UU…6.1
- CVE-2010-3858The setup_arg_pages function in fs/exec.c in the Linux kerne…
- CVE-2010-3859Multiple integer signedness errors in the TIPC implementatio…
- CVE-2010-3861The ethtool_get_rxnfc function in net/core/ethtool.c in the …
- CVE-2010-3862The org.jboss.remoting.transport.bisocket.BisocketServerInvo…
- CVE-2010-3863Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not can…
- CVE-2010-3864Multiple race conditions in ssl/t1_lib.c in OpenSSL 0.9.8f t…
- CVE-2010-3865Integer overflow in the rds_rdma_pages function in net/rds/r…
- CVE-2010-3866Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
Are you affected by CVE-2010-3860?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
