Vulnerability Name:

CVE-2010-0850 (CCN-57350)

Assigned:2010-03-30
Published:2010-03-30
Updated:2018-10-10
Summary:Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2010-0850

Source: CCN
Type: HP Security Bulletin HPSBMA02547 SSRT100189
HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows, Remote Execution of Arbitrary Code and Other Vulnerabilities

Source: HP
Type: UNKNOWN
SSRT100179

Source: SUSE
Type: UNKNOWN
SUSE-SR:2010:008

Source: HP
Type: UNKNOWN
HPSBMU02799

Source: CCN
Type: SA37255
Sun Java JDK / JRE Multiple Vulnerabilities

Source: CCN
Type: SA39317
SUSE Update for Multiple Packages

Source: SECUNIA
Type: UNKNOWN
39317

Source: CCN
Type: SA40545
HP Systems Insight Manager Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
40545

Source: CCN
Type: SA43308
VMware vCenter / ESX Server Update for Oracle (Sun) JRE

Source: SECUNIA
Type: UNKNOWN
43308

Source: CCN
Type: Oracle Critical Patch Update Advisory - March 2010
Oracle Java SE and Java for Business Critical Patch Update Advisory - March 2015

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/javacpumar2010-083341.html

Source: CCN
Type: OSVDB ID: 63501
Oracle Java SE / Java for Business Java 2D Unspecified Unauthenticated Remote Issue (2010-0850)

Source: BUGTRAQ
Type: UNKNOWN
20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX

Source: CCN
Type: BID-39082
Oracle Java SE and Java for Business CVE-2010-0850 Remote Java 2D Vulnerability

Source: CONFIRM
Type: UNKNOWN
http://www.vmware.com/security/advisories/VMSA-2011-0003.html

Source: CONFIRM
Type: UNKNOWN
http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html

Source: VUPEN
Type: UNKNOWN
ADV-2010-1793

Source: XF
Type: UNKNOWN
javase-javab-java2d-unspecified-var4(57350)

Source: SUSE
Type: SUSE-SR:2010:008
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sun:jdk:1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.0_01:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.0_02:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.0_03:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.0_04:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.0_05:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1:-:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_01:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_01a:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_02:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_03:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_04:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_05:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_06:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_07:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_08:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_09:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_10:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_11:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_12:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_13:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_14:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_15:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_16:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_17:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_18:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_19:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_20:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_21:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_22:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_23:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_24:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_25:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:1.3.1_26:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jdk:*:*:*:*:*:*:*:* (Version <= 1.3.1_27)

  • Configuration 2:
  • cpe:/a:sun:jre:1.3.0:-:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.0:update1:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.0:update2:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.0:update3:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.0:update4:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.0:update5:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1:-:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1:update1:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1:update2:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_2:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_03:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_04:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_05:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_06:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_07:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_08:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_09:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_10:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_11:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_12:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_13:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_14:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_15:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_16:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_17:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_18:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_19:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_20:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_21:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_22:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_23:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_24:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_25:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:1.3.1_26:*:*:*:*:*:*:*
  • OR cpe:/a:sun:jre:*:*:*:*:*:*:*:* (Version <= 1.3.1_27)

  • Configuration 3:
  • cpe:/a:sun:sdk:1.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.0_01:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.0_02:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.0_03:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.0_04:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.0_05:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_01:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_01a:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_02:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_03:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_04:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_05:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_06:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_07:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_08:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_09:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_10:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_11:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_12:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_13:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_14:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_15:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_16:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_17:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_18:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_19:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_20:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_21:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_22:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_23:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_24:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_25:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_26:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:*:*:*:*:*:*:*:* (Version <= 1.3.1_27)

  • Configuration CCN 1:
  • cpe:/a:hp:systems_insight_manager:4.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.1:sp1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.2:sp1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.2:sp2:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp2:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp3:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp4:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:sp5:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:-:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.1:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:4.2:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.2:*:*:*:*:*:*:*
  • OR cpe:/a:sun:sdk:1.3.1_27:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.3:*:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:5.3:update_1:*:*:*:*:*:*
  • OR cpe:/a:hp:systems_insight_manager:6.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:sun:jdk:1.3.1_27:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20100850
    V
    CVE-2010-0850
    2015-11-16
    BACK
    sun jdk 1.3.0
    sun jdk 1.3.0_01
    sun jdk 1.3.0_02
    sun jdk 1.3.0_03
    sun jdk 1.3.0_04
    sun jdk 1.3.0_05
    sun jdk 1.3.1
    sun jdk 1.3.1_01
    sun jdk 1.3.1_01a
    sun jdk 1.3.1_02
    sun jdk 1.3.1_03
    sun jdk 1.3.1_04
    sun jdk 1.3.1_05
    sun jdk 1.3.1_06
    sun jdk 1.3.1_07
    sun jdk 1.3.1_08
    sun jdk 1.3.1_09
    sun jdk 1.3.1_10
    sun jdk 1.3.1_11
    sun jdk 1.3.1_12
    sun jdk 1.3.1_13
    sun jdk 1.3.1_14
    sun jdk 1.3.1_15
    sun jdk 1.3.1_16
    sun jdk 1.3.1_17
    sun jdk 1.3.1_18
    sun jdk 1.3.1_19
    sun jdk 1.3.1_20
    sun jdk 1.3.1_21
    sun jdk 1.3.1_22
    sun jdk 1.3.1_23
    sun jdk 1.3.1_24
    sun jdk 1.3.1_25
    sun jdk 1.3.1_26
    sun jdk *
    sun jre 1.3.0
    sun jre 1.3.0 update1
    sun jre 1.3.0 update2
    sun jre 1.3.0 update3
    sun jre 1.3.0 update4
    sun jre 1.3.0 update5
    sun jre 1.3.1
    sun jre 1.3.1 update1
    sun jre 1.3.1 update2
    sun jre 1.3.1_2
    sun jre 1.3.1_03
    sun jre 1.3.1_04
    sun jre 1.3.1_05
    sun jre 1.3.1_06
    sun jre 1.3.1_07
    sun jre 1.3.1_08
    sun jre 1.3.1_09
    sun jre 1.3.1_10
    sun jre 1.3.1_11
    sun jre 1.3.1_12
    sun jre 1.3.1_13
    sun jre 1.3.1_14
    sun jre 1.3.1_15
    sun jre 1.3.1_16
    sun jre 1.3.1_17
    sun jre 1.3.1_18
    sun jre 1.3.1_19
    sun jre 1.3.1_20
    sun jre 1.3.1_21
    sun jre 1.3.1_22
    sun jre 1.3.1_23
    sun jre 1.3.1_24
    sun jre 1.3.1_25
    sun jre 1.3.1_26
    sun jre *
    sun sdk 1.3.0
    sun sdk 1.3.0_01
    sun sdk 1.3.0_02
    sun sdk 1.3.0_03
    sun sdk 1.3.0_04
    sun sdk 1.3.0_05
    sun sdk 1.3.1
    sun sdk 1.3.1_01
    sun sdk 1.3.1_01a
    sun sdk 1.3.1_02
    sun sdk 1.3.1_03
    sun sdk 1.3.1_04
    sun sdk 1.3.1_05
    sun sdk 1.3.1_06
    sun sdk 1.3.1_07
    sun sdk 1.3.1_08
    sun sdk 1.3.1_09
    sun sdk 1.3.1_10
    sun sdk 1.3.1_11
    sun sdk 1.3.1_12
    sun sdk 1.3.1_13
    sun sdk 1.3.1_14
    sun sdk 1.3.1_15
    sun sdk 1.3.1_16
    sun sdk 1.3.1_17
    sun sdk 1.3.1_18
    sun sdk 1.3.1_19
    sun sdk 1.3.1_20
    sun sdk 1.3.1_21
    sun sdk 1.3.1_22
    sun sdk 1.3.1_23
    sun sdk 1.3.1_24
    sun sdk 1.3.1_25
    sun sdk 1.3.1_26
    sun sdk *
    hp systems insight manager 4.0 sp1
    hp systems insight manager 4.1 sp1
    hp systems insight manager 4.2 sp1
    hp systems insight manager 4.2 sp2
    hp systems insight manager 5.0 sp1
    hp systems insight manager 5.0 sp2
    hp systems insight manager 5.0 sp3
    hp systems insight manager 5.0 sp4
    hp systems insight manager 5.0 sp5
    hp systems insight manager -
    hp systems insight manager 4.0
    hp systems insight manager 4.1
    hp systems insight manager 4.2
    hp systems insight manager 5.0
    hp systems insight manager 5.2
    sun sdk 1.3.1_27
    hp systems insight manager 5.3
    hp systems insight manager 5.3 update_1
    hp systems insight manager 6.0
    sun jdk 1.3.1_27