Vulnerability Name: | CVE-2010-4472 (CCN-65411) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2010-12-06 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Published: | 2011-02-15 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2017-12-22 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Summary: | Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect availability, related to XML Digital Signature and unspecified APIs. Note: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue involves the replacement of the "XML DSig Transform or C14N algorithm implementations." | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P) 1.9 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
1.9 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2010-4472 Source: FEDORA Type: UNKNOWN FEDORA-2011-1631 Source: FEDORA Type: UNKNOWN FEDORA-2011-1645 Source: HP Type: UNKNOWN HPSBMU02799 Source: HP Type: UNKNOWN SSRT100867 Source: CCN Type: RHSA-2011-0281 Important: java-1.6.0-openjdk security update Source: CCN Type: RHSA-2011-0282 Critical: java-1.6.0-sun security update Source: SECUNIA Type: Vendor Advisory 43350 Source: CCN Type: SA43627 Hitachi Cosminexus Products Java Multiple Vulnerabilities Source: CCN Type: SA44291 Oracle JRockit Multiple Vulnerabilities Source: GENTOO Type: UNKNOWN GLSA-201406-32 Source: DEBIAN Type: UNKNOWN DSA-2224 Source: DEBIAN Type: DSA-2224 openjdk-6 -- several vulnerabilities Source: CCN Type: Hitachi Security Vulnerability Information HS11-003 Multiple Vulnerabilities in Cosminexus Source: CONFIRM Type: UNKNOWN http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS11-003/index.html Source: MANDRIVA Type: UNKNOWN MDVSA-2011:054 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html Source: CCN Type: Oracle Critical Patch Update - February 2011 Oracle Java SE and Java for Business Critical Patch Update Advisory - February 2011 Source: CONFIRM Type: Patch, Vendor Advisory http://www.oracle.com/technetwork/topics/security/javacpufeb2011-304611.html Source: CCN Type: OSVDB ID: 71622 Oracle Java SE / Java for Business XML Digital Signature Unspecified Remote DoS Source: REDHAT Type: Vendor Advisory RHSA-2011:0281 Source: REDHAT Type: Vendor Advisory RHSA-2011:0282 Source: BID Type: UNKNOWN 46404 Source: CCN Type: BID-46404 Oracle Java SE and Java for Business CVE-2010-4472 Remote Java Runtime Environment Vulnerability Source: XF Type: UNKNOWN oracle-java-xml-dos(65411) Source: XF Type: UNKNOWN oracle-java-xml-dos(65411) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:12903 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:14118 Source: SUSE Type: SUSE-SA:2011:010 Sun Java Security update | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
BACK |