// For flags

CVE-2009-3884

OpenJDK zoneinfo file existence information leak (6824265)

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.

El método TimeZone.getTimeZone en Sun Java SE 5.0 antes de Update22, Sun Java SE 6.0 antes de la actualización 17, y OpenJDK, permite a atacantes remotos determinar la existencia de archivos locales a través de vectores relacionados con el manejo de ficheros zoneinfo (aliasa TZ). Se trata del Bug ID 6824265.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-11-05 CVE Reserved
  • 2009-11-09 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
<= 1.5.0
Search vendor "Sun" for product "Jre" and version " <= 1.5.0"
update_21
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
<= 1.6.0
Search vendor "Sun" for product "Jre" and version " <= 1.6.0"
update_16
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_1
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_11
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_12
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_13
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_14
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_15
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_16
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_17
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_18
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_19
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_2
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_20
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_3
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_4
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_5
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_6
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_7
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_8
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update_9
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.5.0
Search vendor "Sun" for product "Jre" and version "1.5.0"
update10
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_1
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_10
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_11
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_12
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_13
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_14
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_15
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_2
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_3
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_4
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_5
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_6
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_7
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_8
Affected
Sun
Search vendor "Sun"
Jre
Search vendor "Sun" for product "Jre"
1.6.0
Search vendor "Sun" for product "Jre" and version "1.6.0"
update_9
Affected
Sun
Search vendor "Sun"
Openjdk
Search vendor "Sun" for product "Openjdk"
*-
Affected