{"api_version":"1","generated_at":"2026-07-23T07:35:45+00:00","cve":"CVE-2004-1489","urls":{"html":"https://cve.report/CVE-2004-1489","api":"https://cve.report/api/cve/CVE-2004-1489.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1489","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1489"},"summary":{"title":"CVE-2004-1489","description":"Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-668","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.6","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml","name":"http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"Gentoo Linux Documentation\n--\n  Opera: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.opera.com/linux/changelogs/754u1/","name":"http://www.opera.com/linux/changelogs/754u1/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Changelog for Opera 7.54u1 for Linux","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029044.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029044.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"[Full-Disclosure] Mailing List Charter","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1489","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1489","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1489","vulnerable":"1","versionEndIncluding":"7.54","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opera","cpe5":"opera_browser","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:53:24.100Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.opera.com/linux/changelogs/754u1/"},{"name":"20041119 Java Vulnerabilities in Opera 7.54","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029044.html"},{"name":"GLSA-200502-17","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-11-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-03-21T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.opera.com/linux/changelogs/754u1/"},{"name":"20041119 Java Vulnerabilities in Opera 7.54","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029044.html"},{"name":"GLSA-200502-17","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1489","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.opera.com/linux/changelogs/754u1/","refsource":"CONFIRM","url":"http://www.opera.com/linux/changelogs/754u1/"},{"name":"20041119 Java Vulnerabilities in Opera 7.54","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029044.html"},{"name":"GLSA-200502-17","refsource":"GENTOO","url":"http://www.gentoo.org/security/en/glsa/glsa-200502-17.xml"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1489","datePublished":"2005-02-17T05:00:00.000Z","dateReserved":"2005-02-17T00:00:00.000Z","dateUpdated":"2024-08-08T00:53:24.100Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-668","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opera:opera_browser:*:*:*:*:*:*:*:*","versionEndIncluding":"7.54","matchCriteriaId":"BFE75E76-E20D-47A4-9603-0AF46F733AEF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1489","Ordinal":"1","Title":"CVE-2004-1489","CVE":"CVE-2004-1489","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1489","Ordinal":"1","NoteData":"Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.","Type":"Description","Title":"CVE-2004-1489"},{"CveYear":"2004","CveId":"1489","Ordinal":"2","NoteData":"2005-02-17","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1489","Ordinal":"3","NoteData":"2005-03-21","Type":"Other","Title":"Modified"}]}}}