Vulnerability Name: | CCN-84017 | ||||||
Published: | 2013-05-06 | ||||||
Updated: | 2013-05-06 | ||||||
Summary: | Oracle Java could allow a remote attacker to bypass security restrictions, caused by the failure to perform applet's signature check by the performSSVValidation method implementation when combined with JNLP. If set to "true", an attacker could exploit this vulnerability using the __applet_ssv_validated undocumented parameter to bypass the Security Warning pop-up window. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||
CVSS v2 Severity: | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Bypass Security | ||||||
References: | Source: CCN Type: Immunity Web Site Yet Another Java Security Warning Bypass Source: CCN Type: Oracle Web site Oracle Java Source: XF Type: UNKNOWN oracle-performssvalidation-sec-bypass(84017) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |