|
|||
Rule General Information |
---|
Release Date: | 2010-11-18 | |
Rule Name: | WEB-OTHER Oracle Java Web Start Launch Command-Line injection -3 | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | The vulnerability is caused due to an input sanitation error in the Java Deployment Toolkit browser plugin. This can be exploited to pass arbitrary arguments to javaw.exe and e.g. execute a JAR file placed on a network share in a privileged context. | |
Impact: | Remote code execution | |
Affected OS: | Network Device, Solaris, FreeBSD, Windows, Other Unix, Linux | |
Reference: | SecurityAdvisory:SA39260 |
|
Solutions |
---|
Update vendor's patch. |