Skip to content

Unspecified vulnerability in the Java Runtime Environment...

High severity Unreviewed Published May 2, 2022 to the GitHub Advisory Database • Updated Jun 28, 2024

Package

No package listedSuggest a package

Affected versions

Unknown

Patched versions

Unknown

Description

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."

References

Published by the National Vulnerability Database Apr 1, 2010
Published to the GitHub Advisory Database May 2, 2022
Last updated Jun 28, 2024

Severity

High

EPSS score

94.769%
(99th percentile)

Weaknesses

No CWEs

CVE ID

CVE-2010-0840

GHSA ID

GHSA-8rrv-3xx7-wmfc

Source code

No known source code

Dependabot alerts are not supported on this advisory because it does not have a package from a supported ecosystem with an affected and fixed version.

Learn more about GitHub language support

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.