Vulnerability Name: | CVE-2010-0887 (CCN-57844) | ||||||||||||||||||||||||||||||||
Assigned: | 2010-04-09 | ||||||||||||||||||||||||||||||||
Published: | 2010-04-09 | ||||||||||||||||||||||||||||||||
Updated: | 2016-08-23 | ||||||||||||||||||||||||||||||||
Summary: | Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business JDK and JRE 6 Update 18 and 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||
References: | Source: CCN Type: The Oracle Global Product Security Blog Security Alert for CVE-2010-0886 and CVE-2010-0887 Released Source: MITRE Type: CNA CVE-2010-0887 Source: APPLE Type: UNKNOWN APPLE-SA-2010-05-18-1 Source: APPLE Type: UNKNOWN APPLE-SA-2010-05-18-2 Source: HP Type: UNKNOWN HPSBMU02799 Source: CCN Type: RHSA-2010-0356 Critical: java-1.6.0-sun security update Source: CCN Type: RHSA-2010-0549 Critical: java-1.6.0-ibm security update Source: CCN Type: SA39819 Apple Mac OS X update for Java Source: SECUNIA Type: UNKNOWN 39819 Source: CCN Type: SA40773 IBM Java Plugin Argument Injection Vulnerability Source: CONFIRM Type: UNKNOWN http://support.apple.com/kb/HT4170 Source: CONFIRM Type: UNKNOWN http://support.apple.com/kb/HT4171 Source: CCN Type: IBM Security alerts Oracle 1.6.0_20 Emergency Release Source: CCN Type: Oracle Security Alert CVE-2010-0886 Oracle Security Alert CVE-2010-0886 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0886.html Source: CCN Type: OSVDB ID: 63799 Oracle Java SE / Java for Business Plug-in Unspecified Remote Code Execution Source: VUPEN Type: UNKNOWN ADV-2010-1191 Source: XF Type: UNKNOWN java-business-npapi-command-execution(57844) | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |