{"api_version":"1","generated_at":"2026-07-23T07:39:14+00:00","cve":"CVE-2008-3109","urls":{"html":"https://cve.report/CVE-2008-3109","api":"https://cve.report/api/cve/CVE-2008-3109.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3109","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3109"},"summary":{"title":"CVE-2008-3109","description":"Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-07-09 23:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.us-cert.gov/cas/techalerts/TA08-193A.html","name":"http://www.us-cert.gov/cas/techalerts/TA08-193A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA08-193A -- Sun Java Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-1045.html","name":"http://www.redhat.com/support/errata/RHSA-2008-1045.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/30144","name":"http://www.securityfocus.com/bid/30144","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Sun Java Runtime Environment Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/33238","name":"http://secunia.com/advisories/33238","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat update for java-1.6.0-bea - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31600","name":"http://secunia.com/advisories/31600","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SUSE update for Sun Java - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1020456","name":"http://www.securitytracker.com/id?1020456","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Java Runtime Environment (JRE) Scripting Language Bugs Let Remote Users Access Files and Gain Privileges on the Target System","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32436","name":"http://secunia.com/advisories/32436","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat update for java-1.6.0-ibm - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/2740","name":"http://www.vupen.com/english/advisories/2008/2740","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/2056/references","name":"http://www.vupen.com/english/advisories/2008/2056/references","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31010","name":"http://secunia.com/advisories/31010","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Sun Java JDK / JRE Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32018","name":"http://secunia.com/advisories/32018","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mac OS X Java Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-200911-02.xml","name":"http://security.gentoo.org/glsa/glsa-200911-02.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux Documentation\n--\n  Sun JDK/JRE: Multiple vulnerabilites","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vmware.com/security/advisories/VMSA-2008-0016.html","name":"http://www.vmware.com/security/advisories/VMSA-2008-0016.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VMSA-2008-0016.2 - VMware","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32179","name":"http://secunia.com/advisories/32179","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VMware VirtualCenter Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/37386","name":"http://secunia.com/advisories/37386","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo updates for sun-jre-bin, sun-jdk, blackdown-jre, blackdown-jdk, and emul-linux-x86-java - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0906.html","name":"http://www.redhat.com/support/errata/RHSA-2008-0906.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43660","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43660","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=122331139823057&w=2","name":"http://marc.info/?l=bugtraq&m=122331139823057&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00007.html","name":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00007.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2008-09-24 Java for Mac OS X 10.5 Update 2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-238687-1","name":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-238687-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"#238687: Security Vulnerabilities in the Java Runtime Environment Scripting Language Support","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/497041/100/0/threaded","name":"http://www.securityfocus.com/archive/1/497041/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT3179","name":"http://support.apple.com/kb/HT3179","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of Java for Mac OS X 10.5 Update 2","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.html","name":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE Security Announcement: Sun Java (SUSE-SA:2008:0","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8540","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8540","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2008-509.htm","name":"http://support.avaya.com/elmodocs2/security/ASA-2008-509.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ASA-2008-509 (RHSA-2008-1045)","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2008-428.htm","name":"http://support.avaya.com/elmodocs2/security/ASA-2008-428.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ASA-2008-428 (RHSA-2008-0906)","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0594.html","name":"http://www.redhat.com/support/errata/RHSA-2008-0594.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32180","name":"http://secunia.com/advisories/32180","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VMware ESX Server Sun Java JDK / JRE Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3109","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3109","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3109","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jdk","cpe6":"6","cpe7":"update_1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3109","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jdk","cpe6":"6","cpe7":"update_2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3109","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jdk","cpe6":"6","cpe7":"update_3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3109","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jdk","cpe6":"6","cpe7":"update_4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3109","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jdk","cpe6":"6","cpe7":"update_5","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3109","vulnerable":"1","versionEndIncluding":"6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jdk","cpe6":"*","cpe7":"update_6","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3109","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jre","cpe6":"6","cpe7":"update_1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3109","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jre","cpe6":"6","cpe7":"update_2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3109","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jre","cpe6":"6","cpe7":"update_3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3109","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jre","cpe6":"6","cpe7":"update_4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3109","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jre","cpe6":"6","cpe7":"update_5","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3109","vulnerable":"1","versionEndIncluding":"6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sun","cpe5":"jre","cpe6":"*","cpe7":"update_6","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:28:41.157Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=122331139823057&w=2"},{"name":"32436","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32436"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2008-428.htm"},{"name":"31600","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31600"},{"name":"SUSE-SA:2008:042","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.html"},{"name":"32018","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32018"},{"name":"sun-jre-scripting-unauth-access(43660)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43660"},{"name":"238687","tags":["vendor-advisory","x_refsource_SUNALERT","x_transferred"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-238687-1"},{"name":"GLSA-200911-02","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-200911-02.xml"},{"name":"32179","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32179"},{"name":"ADV-2008-2740","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/2740"},{"name":"30144","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30144"},{"name":"APPLE-SA-2008-09-24","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00007.html"},{"name":"ADV-2008-2056","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/2056/references"},{"name":"32180","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32180"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2008-0016.html"},{"name":"oval:org.mitre.oval:def:8540","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8540"},{"name":"RHSA-2008:0594","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0594.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2008-509.htm"},{"name":"RHSA-2008:1045","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-1045.html"},{"name":"33238","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33238"},{"name":"1020456","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1020456"},{"name":"20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/497041/100/0/threaded"},{"name":"RHSA-2008:0906","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0906.html"},{"name":"TA08-193A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-193A.html"},{"name":"37386","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37386"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT3179"},{"name":"31010","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31010"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-07-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=122331139823057&w=2"},{"name":"32436","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32436"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2008-428.htm"},{"name":"31600","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31600"},{"name":"SUSE-SA:2008:042","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.html"},{"name":"32018","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32018"},{"name":"sun-jre-scripting-unauth-access(43660)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43660"},{"name":"238687","tags":["vendor-advisory","x_refsource_SUNALERT"],"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-238687-1"},{"name":"GLSA-200911-02","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-200911-02.xml"},{"name":"32179","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32179"},{"name":"ADV-2008-2740","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/2740"},{"name":"30144","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30144"},{"name":"APPLE-SA-2008-09-24","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00007.html"},{"name":"ADV-2008-2056","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/2056/references"},{"name":"32180","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32180"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2008-0016.html"},{"name":"oval:org.mitre.oval:def:8540","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8540"},{"name":"RHSA-2008:0594","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0594.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2008-509.htm"},{"name":"RHSA-2008:1045","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-1045.html"},{"name":"33238","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33238"},{"name":"1020456","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1020456"},{"name":"20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/497041/100/0/threaded"},{"name":"RHSA-2008:0906","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0906.html"},{"name":"TA08-193A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-193A.html"},{"name":"37386","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37386"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT3179"},{"name":"31010","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31010"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3109","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=122331139823057&w=2"},{"name":"32436","refsource":"SECUNIA","url":"http://secunia.com/advisories/32436"},{"name":"http://support.avaya.com/elmodocs2/security/ASA-2008-428.htm","refsource":"CONFIRM","url":"http://support.avaya.com/elmodocs2/security/ASA-2008-428.htm"},{"name":"31600","refsource":"SECUNIA","url":"http://secunia.com/advisories/31600"},{"name":"SUSE-SA:2008:042","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.html"},{"name":"32018","refsource":"SECUNIA","url":"http://secunia.com/advisories/32018"},{"name":"sun-jre-scripting-unauth-access(43660)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43660"},{"name":"238687","refsource":"SUNALERT","url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-238687-1"},{"name":"GLSA-200911-02","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-200911-02.xml"},{"name":"32179","refsource":"SECUNIA","url":"http://secunia.com/advisories/32179"},{"name":"ADV-2008-2740","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/2740"},{"name":"30144","refsource":"BID","url":"http://www.securityfocus.com/bid/30144"},{"name":"APPLE-SA-2008-09-24","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00007.html"},{"name":"ADV-2008-2056","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/2056/references"},{"name":"32180","refsource":"SECUNIA","url":"http://secunia.com/advisories/32180"},{"name":"http://www.vmware.com/security/advisories/VMSA-2008-0016.html","refsource":"CONFIRM","url":"http://www.vmware.com/security/advisories/VMSA-2008-0016.html"},{"name":"oval:org.mitre.oval:def:8540","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8540"},{"name":"RHSA-2008:0594","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2008-0594.html"},{"name":"http://support.avaya.com/elmodocs2/security/ASA-2008-509.htm","refsource":"CONFIRM","url":"http://support.avaya.com/elmodocs2/security/ASA-2008-509.htm"},{"name":"RHSA-2008:1045","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2008-1045.html"},{"name":"33238","refsource":"SECUNIA","url":"http://secunia.com/advisories/33238"},{"name":"1020456","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1020456"},{"name":"20081004 VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/497041/100/0/threaded"},{"name":"RHSA-2008:0906","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2008-0906.html"},{"name":"TA08-193A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA08-193A.html"},{"name":"37386","refsource":"SECUNIA","url":"http://secunia.com/advisories/37386"},{"name":"http://support.apple.com/kb/HT3179","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT3179"},{"name":"31010","refsource":"SECUNIA","url":"http://secunia.com/advisories/31010"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3109","datePublished":"2008-07-09T23:00:00.000Z","dateReserved":"2008-07-09T00:00:00.000Z","dateUpdated":"2024-08-07T09:28:41.157Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-07-09 23:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jdk:*:update_6:*:*:*:*:*:*","versionEndIncluding":"6","matchCriteriaId":"94A87B01-2F20-4E1C-8572-395A96C35D79"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jdk:6:update_1:*:*:*:*:*:*","matchCriteriaId":"9C9F6EA8-6A88-4485-89A3-0FDF84AB51DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jdk:6:update_2:*:*:*:*:*:*","matchCriteriaId":"67E0818A-3675-4293-89FE-5001E36C0F38"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jdk:6:update_3:*:*:*:*:*:*","matchCriteriaId":"95112B98-B6B2-43FA-BF76-F518649CF3BE"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jdk:6:update_4:*:*:*:*:*:*","matchCriteriaId":"3A18341A-3688-48E7-95AD-283EC9C95B4A"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jdk:6:update_5:*:*:*:*:*:*","matchCriteriaId":"E301C59A-47F5-4861-9091-D0002CBA5B7A"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jre:*:update_6:*:*:*:*:*:*","versionEndIncluding":"6","matchCriteriaId":"2A1D1D91-B29F-4335-A7DA-FF988F626907"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jre:6:update_1:*:*:*:*:*:*","matchCriteriaId":"0F98D2BD-2AC1-4C4C-8A10-71093DCBC4E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jre:6:update_2:*:*:*:*:*:*","matchCriteriaId":"CDC09958-5286-4C16-AB6F-63B4BDD902B3"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jre:6:update_3:*:*:*:*:*:*","matchCriteriaId":"BDE1E9E9-85EF-4ACA-902B-00225EB4324F"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jre:6:update_4:*:*:*:*:*:*","matchCriteriaId":"E0CDBFCB-42EA-4F19-A98D-7696B0D526CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:sun:jre:6:update_5:*:*:*:*:*:*","matchCriteriaId":"53DCFF2A-77A7-41DB-A712-9B6D1FD2574A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3109","Ordinal":"1","Title":"CVE-2008-3109","CVE":"CVE-2008-3109","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3109","Ordinal":"1","NoteData":"Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.","Type":"Description","Title":"CVE-2008-3109"},{"CveYear":"2008","CveId":"3109","Ordinal":"2","NoteData":"2008-07-09","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3109","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}