CVE-2008-2086
Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3) user.home System Properties, aka "Java Web Start File Inclusion" and CR 6694892.
- Affected products
- Hp-Ux, Jdk, Jre, Java Platform, Sdk
- Sun Jdk
- ≤ 5.0, 6
- Sun Jre
- ≤ 1.4.2_18, 5.0, 6, 1.4.2_1, 1.4.2_2, 1.4.2_3, 1.4.2_4, 1.4.2_5, 1.4.2_6, 1.4.2_7, 1.4.2_8, 1.4.2_9, 1.4.2_10, 1.4.2_11, 1.4.2_12, 1.4.2_13, 1.4.2_14, 1.4.2_15, 1.4.2_16, 1.4.2_17
- Sun Sdk
- ≤ 1.4.2_18, 1.4.2_1, 1.4.2_2, 1.4.2_3, 1.4.2_4, 1.4.2_5, 1.4.2_6, 1.4.2_7, 1.4.2_8, 1.4.2_9, 1.4.2_10, 1.4.2_11, 1.4.2_12, 1.4.2_13, 1.4.2_14, 1.4.2_15, 1.4.2_16, 1.4.2_17
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 7.3% (94th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2008-12-05
CVE-2008-2086 at NVD
1 known exploit for CVE-2008-2086
Proof-of-concept code and exploit modules indexed by Sploitus