// For flags

CVE-2008-3104

Java RE allows Same Origin Policy to be Bypassed (6687932)

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allow remote attackers to violate the security model for an applet's outbound connections by connecting to localhost services running on the machine that loaded the applet.

Múltiples vulnerabilidades sin especificar en Sun Java Runtime Environment (JRE) en JDK y JRE 6 antes de Update 7, JDK y JRE 5.0 antes de Update 16, SDK y JRE 1.4.x antes de 1.4.2_18, y SDK y JRE 1.3.x antes de 1.3.1_23 permiten a atacantes remotos violar el modelo de seguridad para conexiones de salida de un applet conectándose a servicios del localhost que se están ejecutando en la máquina que cargó el applet.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-07-09 CVE Reserved
  • 2008-07-09 CVE Published
  • 2023-03-30 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (51)
URL Tag Source
http://marc.info/?l=bugtraq&m=122331139823057&w=2 Mailing List
http://secunia.com/advisories/31055 Third Party Advisory
http://secunia.com/advisories/31269 Third Party Advisory
http://secunia.com/advisories/31320 Third Party Advisory
http://secunia.com/advisories/31497 Third Party Advisory
http://secunia.com/advisories/31600 Third Party Advisory
http://secunia.com/advisories/31736 Third Party Advisory
http://secunia.com/advisories/32018 Third Party Advisory
http://secunia.com/advisories/32179 Third Party Advisory
http://secunia.com/advisories/32180 Third Party Advisory
http://secunia.com/advisories/32436 Third Party Advisory
http://secunia.com/advisories/32826 Third Party Advisory
http://secunia.com/advisories/33194 Third Party Advisory
http://secunia.com/advisories/33236 Third Party Advisory
http://secunia.com/advisories/33237 Third Party Advisory
http://secunia.com/advisories/33238 Third Party Advisory
http://secunia.com/advisories/35065 Third Party Advisory
http://secunia.com/advisories/37386 Third Party Advisory
http://support.apple.com/kb/HT3178 X_refsource_confirm
http://support.apple.com/kb/HT3179 X_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2008-428.htm X_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2008-507.htm X_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2008-509.htm X_refsource_confirm
http://www.securityfocus.com/archive/1/497041/100/0/threaded Mailing List
http://www.securityfocus.com/bid/30140 Vdb Entry
http://www.securitytracker.com/id?1020459 Vdb Entry
http://www.us-cert.gov/cas/techalerts/TA08-193A.html Third Party Advisory
http://www.vmware.com/security/advisories/VMSA-2008-0016.html X_refsource_confirm
http://www.vupen.com/english/advisories/2008/2056/references Vdb Entry
http://www.vupen.com/english/advisories/2008/2740 Vdb Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/43662 Vdb Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9565 Signature
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
<= 5.0
Search vendor "Sun" for product "Jdk" and version " <= 5.0"
update_15
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
<= 6
Search vendor "Sun" for product "Jdk" and version " <= 6"
update_6
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
1.5.0
Search vendor "Sun" for product "Jdk" and version "1.5.0"
update_12
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_1
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_10
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_11
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_12
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_13
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_14
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_2
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_3
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_4
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_5
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_6
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_7
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_8
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
5.0
Search vendor "Sun" for product "Jdk" and version "5.0"
update_9
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_1
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_2
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_3
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_4
Affected
Sun
Search vendor "Sun"
Jdk
Search vendor "Sun" for product "Jdk"
6
Search vendor "Sun" for product "Jdk" and version "6"
update_5
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.0
Search vendor "Sun" for product "Jre" and version "1.3.0"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1
Search vendor "Sun" for product "Jre" and version "1.3.1"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1
Search vendor "Sun" for product "Jre" and version "1.3.1"
update16
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1
Search vendor "Sun" for product "Jre" and version "1.3.1"
update18
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1
Search vendor "Sun" for product "Jre" and version "1.3.1"
update19
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1
Search vendor "Sun" for product "Jre" and version "1.3.1"
update20
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_02
Search vendor "Sun" for product "Jre" and version "1.3.1_02"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_03
Search vendor "Sun" for product "Jre" and version "1.3.1_03"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_04
Search vendor "Sun" for product "Jre" and version "1.3.1_04"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_05
Search vendor "Sun" for product "Jre" and version "1.3.1_05"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_06
Search vendor "Sun" for product "Jre" and version "1.3.1_06"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_07
Search vendor "Sun" for product "Jre" and version "1.3.1_07"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_08
Search vendor "Sun" for product "Jre" and version "1.3.1_08"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_09
Search vendor "Sun" for product "Jre" and version "1.3.1_09"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_10
Search vendor "Sun" for product "Jre" and version "1.3.1_10"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_11
Search vendor "Sun" for product "Jre" and version "1.3.1_11"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_12
Search vendor "Sun" for product "Jre" and version "1.3.1_12"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_13
Search vendor "Sun" for product "Jre" and version "1.3.1_13"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_14
Search vendor "Sun" for product "Jre" and version "1.3.1_14"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_15
Search vendor "Sun" for product "Jre" and version "1.3.1_15"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_17
Search vendor "Sun" for product "Jre" and version "1.3.1_17"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_21
Search vendor "Sun" for product "Jre" and version "1.3.1_21"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.3.1_22
Search vendor "Sun" for product "Jre" and version "1.3.1_22"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_1
Search vendor "Sun" for product "Jre" and version "1.4.2_1"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_2
Search vendor "Sun" for product "Jre" and version "1.4.2_2"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_3
Search vendor "Sun" for product "Jre" and version "1.4.2_3"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_4
Search vendor "Sun" for product "Jre" and version "1.4.2_4"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_5
Search vendor "Sun" for product "Jre" and version "1.4.2_5"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_6
Search vendor "Sun" for product "Jre" and version "1.4.2_6"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_7
Search vendor "Sun" for product "Jre" and version "1.4.2_7"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_8
Search vendor "Sun" for product "Jre" and version "1.4.2_8"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_9
Search vendor "Sun" for product "Jre" and version "1.4.2_9"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_10
Search vendor "Sun" for product "Jre" and version "1.4.2_10"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_11
Search vendor "Sun" for product "Jre" and version "1.4.2_11"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_12
Search vendor "Sun" for product "Jre" and version "1.4.2_12"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_13
Search vendor "Sun" for product "Jre" and version "1.4.2_13"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_14
Search vendor "Sun" for product "Jre" and version "1.4.2_14"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_15
Search vendor "Sun" for product "Jre" and version "1.4.2_15"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_16
Search vendor "Sun" for product "Jre" and version "1.4.2_16"
-
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.4.2_17
Search vendor "Sun" for product "Jre" and version "1.4.2_17"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.0
Search vendor "Sun" for product "Sdk" and version "1.3.0"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_01
Search vendor "Sun" for product "Sdk" and version "1.3.1_01"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_02
Search vendor "Sun" for product "Sdk" and version "1.3.1_02"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_03
Search vendor "Sun" for product "Sdk" and version "1.3.1_03"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_04
Search vendor "Sun" for product "Sdk" and version "1.3.1_04"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_05
Search vendor "Sun" for product "Sdk" and version "1.3.1_05"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_06
Search vendor "Sun" for product "Sdk" and version "1.3.1_06"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_07
Search vendor "Sun" for product "Sdk" and version "1.3.1_07"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_08
Search vendor "Sun" for product "Sdk" and version "1.3.1_08"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_09
Search vendor "Sun" for product "Sdk" and version "1.3.1_09"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_10
Search vendor "Sun" for product "Sdk" and version "1.3.1_10"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_11
Search vendor "Sun" for product "Sdk" and version "1.3.1_11"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_12
Search vendor "Sun" for product "Sdk" and version "1.3.1_12"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_13
Search vendor "Sun" for product "Sdk" and version "1.3.1_13"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_14
Search vendor "Sun" for product "Sdk" and version "1.3.1_14"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_15
Search vendor "Sun" for product "Sdk" and version "1.3.1_15"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_16
Search vendor "Sun" for product "Sdk" and version "1.3.1_16"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_17
Search vendor "Sun" for product "Sdk" and version "1.3.1_17"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_18
Search vendor "Sun" for product "Sdk" and version "1.3.1_18"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_19
Search vendor "Sun" for product "Sdk" and version "1.3.1_19"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_20
Search vendor "Sun" for product "Sdk" and version "1.3.1_20"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_21
Search vendor "Sun" for product "Sdk" and version "1.3.1_21"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.3.1_22
Search vendor "Sun" for product "Sdk" and version "1.3.1_22"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2
Search vendor "Sun" for product "Sdk" and version "1.4.2"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_01
Search vendor "Sun" for product "Sdk" and version "1.4.2_01"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_02
Search vendor "Sun" for product "Sdk" and version "1.4.2_02"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_03
Search vendor "Sun" for product "Sdk" and version "1.4.2_03"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_04
Search vendor "Sun" for product "Sdk" and version "1.4.2_04"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_05
Search vendor "Sun" for product "Sdk" and version "1.4.2_05"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_06
Search vendor "Sun" for product "Sdk" and version "1.4.2_06"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_07
Search vendor "Sun" for product "Sdk" and version "1.4.2_07"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_08
Search vendor "Sun" for product "Sdk" and version "1.4.2_08"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_09
Search vendor "Sun" for product "Sdk" and version "1.4.2_09"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_10
Search vendor "Sun" for product "Sdk" and version "1.4.2_10"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_11
Search vendor "Sun" for product "Sdk" and version "1.4.2_11"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_12
Search vendor "Sun" for product "Sdk" and version "1.4.2_12"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_13
Search vendor "Sun" for product "Sdk" and version "1.4.2_13"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_14
Search vendor "Sun" for product "Sdk" and version "1.4.2_14"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_15
Search vendor "Sun" for product "Sdk" and version "1.4.2_15"
-
Affected
Sun
Search vendor "Sun"
Sdk
Search vendor "Sun" for product "Sdk"
1.4.2_16
Search vendor "Sun" for product "Sdk" and version "1.4.2_16"
-
Affected