Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2010-3573

PUBLISHED 07.08.2024

CNA: oracle

Обновлено: 10.10.2018
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is related to missing validation of request headers in the HttpURLConnection class when they are set by applets, which allows remote attackers to bypass the intended security policy.

EPSS

Вероятность Severity Процентиль ? Дата расчёта
8.41% LOW 92.42 23.05.2026

Exploits & Shellcodes

Идентификатор Тип Описание Дата публикации
EDB-15288 Exploit Oracle JRE - java.net.URLConnection class Same-of-Origin 'SOP' Policy Bypass 20.10.2010

Доп. Информация

Product Status

n/a
Product: n/a
Vendor: n/a
Default status: Не определен
Версии:
Затронутые версии Статус
Наблюдалось в версии n/a affected
 

Ссылки

http://support.avaya.com/css/P8/documents/100114327
http://www.redhat.com/support/errata/RHSA-2010-0865.html
http://support.avaya.com/css/P8/documents/100114315
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://marc.info/?l=bugtraq&m=134254866602253&w=2
http://www.redhat.com/support/errata/RHSA-2010-0770.html
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c02616748
http://www.redhat.com/support/errata/RHSA-2010-0768.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.html
http://www.ubuntu.com/usn/USN-1010-1
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12220
http://www.redhat.com/support/errata/RHSA-2010-0987.html
http://secunia.com/advisories/44954
https://bugzilla.redhat.com/show_bug.cgi?id=642202
http://www.redhat.com/support/errata/RHSA-2011-0880.html
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
http://www.redhat.com/support/errata/RHSA-2010-0873.html
http://www.vmware.com/security/advisories/VMSA-2011-0003.html
http://secunia.com/advisories/42974
http://secunia.com/advisories/41972
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c02616748
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11990
http://support.avaya.com/css/P8/documents/100123193
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html
http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html
http://www.securityfocus.com/archive/1/516397/100/0/threaded
http://secunia.com/advisories/41967
http://www.redhat.com/support/errata/RHSA-2010-0807.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.html

CVE Program Container

Обновлено: 07.08.2024
SSVC and KEV, plus CVSS and CWE if not provided by the CNA.

Ссылки

http://support.avaya.com/css/P8/documents/100114327
http://www.redhat.com/support/errata/RHSA-2010-0865.html
http://support.avaya.com/css/P8/documents/100114315
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://marc.info/?l=bugtraq&m=134254866602253&w=2
http://www.redhat.com/support/errata/RHSA-2010-0770.html
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c02616748
http://www.redhat.com/support/errata/RHSA-2010-0768.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.html
http://www.ubuntu.com/usn/USN-1010-1
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12220
http://www.redhat.com/support/errata/RHSA-2010-0987.html
http://secunia.com/advisories/44954
https://bugzilla.redhat.com/show_bug.cgi?id=642202
http://www.redhat.com/support/errata/RHSA-2011-0880.html
http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html
http://www.redhat.com/support/errata/RHSA-2010-0873.html
http://www.vmware.com/security/advisories/VMSA-2011-0003.html
http://secunia.com/advisories/42974
http://secunia.com/advisories/41972
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c02616748
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11990
http://support.avaya.com/css/P8/documents/100123193
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html
http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html
http://www.securityfocus.com/archive/1/516397/100/0/threaded
http://secunia.com/advisories/41967
http://www.redhat.com/support/errata/RHSA-2010-0807.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.html

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.