Vulnerability Name: CVE-2010-0090 (CCN-57361) Assigned: 2009-12-16 Published: 2010-03-30 Updated: 2018-10-10 Summary: Unspecified vulnerability in the Java Web Start, Java Plug-in component in Oracle Java SE and Java for Business 6 Update 18 allows remote attackers to affect integrity and availability via unknown vectors. Per: http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html
'Affected product releases and versions:
• Java SE:
• JDK and JRE 6 Update 18 and earlier for Windows, Solaris, and Linux
• JDK 5.0 Update 23 and earlier for Solaris
• SDK 1.4.2_25 and earlier for Solaris
• Java for Business:
• JDK and JRE 6 Update 18 and earlier for Windows, Solaris and Linux
• JDK and JRE 5.0 Update 23 and earlier for Windows, Solaris and Linux
• SDK and JRE 1.4.2_25 and earlier for Windows, Solaris and Linux' CVSS v3 Severity: 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P )4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): Partial
5.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P )4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): Partial
5.8 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P )4.3 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2010-0090 Source: CCN Type: HP Security Bulletin HPSBMA02547 SSRT100200HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows, Remote Execution of Arbitrary Code and Other Vulnerabilities Source: HP Type: UNKNOWNSSRT100179 Source: APPLE Type: UNKNOWNAPPLE-SA-2010-05-18-1 Source: APPLE Type: UNKNOWNAPPLE-SA-2010-05-18-2 Source: SUSE Type: UNKNOWNSUSE-SR:2010:008 Source: HP Type: UNKNOWNHPSBMU02799 Source: CCN Type: RHSA-2010-0337Critical: java-1.6.0-sun security update Source: CCN Type: RHSA-2010-0383Critical: java-1.6.0-ibm security update Source: CCN Type: RHSA-2010-0471Low: Red Hat Network Satellite Server IBM Java Runtime security update Source: CCN Type: SA37255Sun Java JDK / JRE Multiple Vulnerabilities Source: CCN Type: SA39317SUSE Update for Multiple Packages Source: SECUNIA Type: Vendor Advisory39317 Source: SECUNIA Type: Vendor Advisory39659 Source: CCN Type: SA39819Apple Mac OS X update for Java Source: SECUNIA Type: Vendor Advisory39819 Source: CCN Type: SA40057IBM Java Multiple Vulnerabilities Source: CCN Type: SA40545HP Systems Insight Manager Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory40545 Source: CCN Type: SA43308VMware vCenter / ESX Server Update for Oracle (Sun) JRE Source: SECUNIA Type: Vendor Advisory43308 Source: CONFIRM Type: UNKNOWNhttp://support.apple.com/kb/HT4170 Source: CONFIRM Type: UNKNOWNhttp://support.apple.com/kb/HT4171 Source: CCN Type: IBM Web sitedeveloperWorks : Java; technology : IBM developer kits : Additional documentation Source: CCN Type: Oracle Critical Patch Update Advisory - March 2010Oracle Java SE and Java for Business Critical Patch Update Advisory - March 2026 Source: CONFIRM Type: UNKNOWNhttp://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html Source: CCN Type: OSVDB ID: 63496Oracle Java SE / Java for Business Java Web Start Plug-in Unspecified Unauthenticated Remote Issue (2010-0090) Source: REDHAT Type: UNKNOWNRHSA-2010:0337 Source: REDHAT Type: UNKNOWNRHSA-2010:0383 Source: REDHAT Type: UNKNOWNRHSA-2010:0471 Source: BUGTRAQ Type: UNKNOWN20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX Source: CCN Type: BID-39091Oracle Java SE and Java for Business CVE-2010-0090 Remote Java Web Start Vulnerability Source: CONFIRM Type: UNKNOWNhttp://www.vmware.com/security/advisories/VMSA-2011-0003.html Source: CONFIRM Type: UNKNOWNhttp://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html Source: VUPEN Type: Vendor AdvisoryADV-2010-1191 Source: VUPEN Type: Vendor AdvisoryADV-2010-1454 Source: VUPEN Type: Vendor AdvisoryADV-2010-1793 Source: XF Type: UNKNOWNjavase-javab-jwsjp-unspecified-var2(57361) Source: OVAL Type: UNKNOWNoval:org.mitre.oval:def:14237 Source: SUSE Type: SUSE-SA:2010:026IBM Java 6 security update Source: SUSE Type: SUSE-SR:2010:008SUSE Security Summary Report Vulnerable Configuration: Configuration 1 :cpe:/a:sun:jre:1.6.0:-:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_1:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_10:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_11:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_12:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_13:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_14:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_15:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_16:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_17:*:*:*:*:*:* OR cpe:/a:sun:jre:*:update_18:*:*:*:*:*:* (Version <= 1.6.0) OR cpe:/a:sun:jre:1.6.0:update_2:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_3:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_4:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_5:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_6:*:*:*:*:*:* OR cpe:/a:sun:jre:1.6.0:update_7:*:*:*:*:*:* Configuration 2 :cpe:/a:sun:jdk:1.6.0:-:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update1:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update1_b06:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update2:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update_10:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update_11:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update_12:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update_13:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update_14:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update_15:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update_16:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update_17:*:*:*:*:*:* OR cpe:/a:sun:jdk:*:update_18:*:*:*:*:*:* (Version <= 1.6.0) OR cpe:/a:sun:jdk:1.6.0:update_3:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update_4:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update_5:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update_6:*:*:*:*:*:* OR cpe:/a:sun:jdk:1.6.0:update_7:*:*:*:*:*:* Configuration RedHat 1 :cpe:/a:redhat:rhel_extras:4:*:*:*:*:*:*:* Configuration RedHat 2 :cpe:/a:redhat:rhel_extras:5:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:hp:systems_insight_manager:4.0:sp1:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:4.1:sp1:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:4.2:sp1:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:4.2:sp2:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:5.0:sp1:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:5.0:sp2:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:5.0:sp3:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:5.0:sp4:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:5.0:sp5:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:-:*:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:4.0:*:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:4.1:*:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:4.2:*:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:5.0:*:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:5.2:*:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:5.3:*:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:5.3:update_1:*:*:*:*:*:* OR cpe:/a:hp:systems_insight_manager:6.0:*:*:*:*:*:*:* AND cpe:/a:redhat:rhel_extras:4:*:*:*:*:*:*:* OR cpe:/a:ibm:java:5.0.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:java:6.0.0.0:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
sun jre 1.6.0
sun jre 1.6.0 update_1
sun jre 1.6.0 update_10
sun jre 1.6.0 update_11
sun jre 1.6.0 update_12
sun jre 1.6.0 update_13
sun jre 1.6.0 update_14
sun jre 1.6.0 update_15
sun jre 1.6.0 update_16
sun jre 1.6.0 update_17
sun jre * update_18
sun jre 1.6.0 update_2
sun jre 1.6.0 update_3
sun jre 1.6.0 update_4
sun jre 1.6.0 update_5
sun jre 1.6.0 update_6
sun jre 1.6.0 update_7
sun jdk 1.6.0
sun jdk 1.6.0 update1
sun jdk 1.6.0 update1_b06
sun jdk 1.6.0 update2
sun jdk 1.6.0 update_10
sun jdk 1.6.0 update_11
sun jdk 1.6.0 update_12
sun jdk 1.6.0 update_13
sun jdk 1.6.0 update_14
sun jdk 1.6.0 update_15
sun jdk 1.6.0 update_16
sun jdk 1.6.0 update_17
sun jdk * update_18
sun jdk 1.6.0 update_3
sun jdk 1.6.0 update_4
sun jdk 1.6.0 update_5
sun jdk 1.6.0 update_6
sun jdk 1.6.0 update_7
hp systems insight manager 4.0 sp1
hp systems insight manager 4.1 sp1
hp systems insight manager 4.2 sp1
hp systems insight manager 4.2 sp2
hp systems insight manager 5.0 sp1
hp systems insight manager 5.0 sp2
hp systems insight manager 5.0 sp3
hp systems insight manager 5.0 sp4
hp systems insight manager 5.0 sp5
hp systems insight manager -
hp systems insight manager 4.0
hp systems insight manager 4.1
hp systems insight manager 4.2
hp systems insight manager 5.0
hp systems insight manager 5.2
hp systems insight manager 5.3
hp systems insight manager 5.3 update_1
hp systems insight manager 6.0
redhat rhel extras 4
ibm java 5.0.0.0
ibm java 6.0.0.0