Multiple Vendor Java Virtual Machine Session Hijacking Vulnerability

BID:4228

Info

Multiple Vendor Java Virtual Machine Session Hijacking Vulnerability

Bugtraq ID: 4228
Class: Design Error
CVE: CVE-2002-0058
Remote: Yes
Local: No
Published: Mar 04 2002 12:00AM
Updated: Jul 11 2009 10:56AM
Credit: Discovered by Harmen van der Wal.
Vulnerable: Sun SDK (Windows Production Release) 1.3 .0_02
Sun SDK (Windows Production Release) 1.1.8 _007
Sun SDK (Solaris Reference Release) 1.2.2 _010
Sun SDK (Solaris Production Release) 1.3 _02
Sun SDK (Solaris Production Release) 1.2.2 _10
Sun SDK (Linux Production Release) 1.3 _02
Sun SDK (Linux Production Release) 1.2.2 _010
Sun JRE (Windows Production Release) 1.3 .0_04
Sun JRE (Windows Production Release) 1.3 .0_02
Sun JRE (Windows Production Release) 1.3
Sun JRE (Windows Production Release) 1.2.2 _010
Sun JRE (Windows Production Release) 1.2.2
Sun JRE (Windows Production Release) 1.1.8 _007
Sun JRE (Windows Production Release) 1.1.8
Sun JRE (Solaris Reference Release) 1.2.2 _010
Sun JRE (Solaris Reference Release) 1.2.2
Sun JRE (Solaris Reference Release) 1.1.8 _007
Sun JRE (Solaris Reference Release) 1.1.8
Sun JRE (Solaris Production Release) 1.3 .0_02
Sun JRE (Solaris Production Release) 1.3
Sun JRE (Solaris Production Release) 1.2.2 _010
Sun JRE (Solaris Production Release) 1.2.2
Sun JRE (Solaris Production Release) 1.1.8 _13
Sun JRE (Solaris Production Release) 1.1.8
Sun JRE (Linux Production Release) 1.3 .0_04
Sun JRE (Linux Production Release) 1.3 .0_02
Sun JRE (Linux Production Release) 1.3 .0_01
Sun JRE (Linux Production Release) 1.2.2 _010
Sun JRE (Linux Production Release) 1.2.2 _003
Sun JDK (Windows Production Release) 1.1.8 _007
Sun JDK (Solaris Reference Release) 1.1.8 _007
Sun JDK (Solaris Production Release) 1.1.8 _13
SGI IRIX 6.5.17
SGI IRIX 6.5.16
SGI IRIX 6.5.15
SGI IRIX 6.5.14
SGI IRIX 6.5.13
SGI IRIX 6.5.12
SGI IRIX 6.5.11
SGI IRIX 6.5.10
SGI IRIX 6.5.9
SGI IRIX 6.5.8
SGI IRIX 6.5.7
SGI IRIX 6.5.6
SGI IRIX 6.5.5
SGI IRIX 6.5.4
SGI IRIX 6.5.3
SGI IRIX 6.5.2
SGI IRIX 6.5.1
SGI IRIX 6.5
Netscape Netscape 6.0 1
- HP HP-UX 11.11
- HP HP-UX 11.0
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Netscape Netscape 6.0
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Netscape Communicator 6.1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0
Microsoft Virtual Machine 3802 Series
+ Microsoft Internet Explorer 5.0.1
+ Microsoft Internet Explorer 4.0.1
+ Microsoft Internet Explorer 5.5
+ Microsoft Internet Explorer 5.0
+ Microsoft Internet Explorer 4.0
HP Java SDK/RTE for HP-UX PA-RISC 1.3
+ HP HP-UX 11.20
+ HP HP-UX 11.11
+ HP HP-UX 11.0
+ HP HP-UX (VVOS) 11.0 4
HP Java SDK/RTE for HP-UX PA-RISC 1.2.2
+ HP HP-UX 11.20
+ HP HP-UX 11.11
+ HP HP-UX 11.0
+ HP HP-UX (VVOS) 11.0 4
HP Java JRE/JDK for HP-UX 1.1.8
+ HP HP-UX 10.20
Compaq Tru64 5.1
Compaq Tru64 5.0 a
Compaq Tru64 4.0 g
Compaq Tru64 4.0 f
Compaq Remote Insight Lights-Out Edition
Compaq OpenVMS 7.3 Alpha
Compaq OpenVMS 7.2.1 Alpha
Compaq OpenVMS 7.2 -2 Alpha
Compaq OpenVMS 7.2 -1H2 Alpha
Compaq OpenVMS 7.2 -1H1 Alpha
Compaq OpenVMS 7.2 Alpha
Compaq Management Agents 4.37 E
Compaq Management Agents 4.36 j
Compaq Management Agents 4.36 E
Compaq Management Agents 4.35 j
Compaq Management Agents 4.30 j
Compaq Integrated Lights-Out on ProLiant DL360 G2
Compaq Insight Manager XE 2.2
Compaq Insight Manager XE 2.1 c
Compaq Insight Manager XE 2.1 b
Compaq Insight Manager XE 2.1
Compaq Insight Manager XE 1.21
Compaq Insight Manager XE 1.0
Compaq Insight Manager 7.0
Not Vulnerable: SGI IRIX 6.5.18
Microsoft Virtual Machine 3805 Series
- Microsoft Internet Explorer 5.0.1 SP2
- Microsoft Internet Explorer 5.0.1 SP1
- Microsoft Internet Explorer 5.0.1
- Microsoft Internet Explorer 6.0
- Microsoft Internet Explorer 5.5 SP2
- Microsoft Internet Explorer 5.5 SP1
- Microsoft Internet Explorer 5.5
- Microsoft Internet Explorer 5.0
Compaq Insight Manager 7.0 SP1

Discussion

Multiple Vendor Java Virtual Machine Session Hijacking Vulnerability

Various Java virtual machine implementations contain a vulnerability that may allow for interception and hijacking of web requests.

The vulnerability is present when a client system is configured to use a HTTP proxy server. It is possible for malicious java code to redirect requests meant for the proxy server to an arbitrary host. This occurs transparently, without any client consent or knowledge.

This vulnerability can be exploited with a maliciously crafted Java applet, possibly embedded in a webpage. The victim must run the applet in a vulnerable virtual machine.

As a result a user's session information could be captured and be examined for sensitive information. Man-in-the-middle attacks may also be possible, as the response to any request may be crafted by the attacker.

It should be noted that all builds of Microsoft Virtual Machine prior to and including build 3802 are affected by this issue.

Exploit / POC

Multiple Vendor Java Virtual Machine Session Hijacking Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Multiple Vendor Java Virtual Machine Session Hijacking Vulnerability

Solution:
Sun SDK and JRE version 1.4 is not vulnerable. It is available at:

http://java.sun.com/j2se/1.4/

Users of Netscape web clients for various platforms should also ensure that the plug-in virtual machines are not vulnerable. HP has updated Java VM plug-ins (JPI) available for Netscape on HP-UX at: http://www.hp.com/go/java.

Compaq Insight Manager XE has been replaced by Compaq Insight Manager 7. Users should upgrade to Compaq Insight Manager 7 and then apply SP 1.

Some versions of Compaq TRU64 Unix and OpenVMS for Alpha ship with vulnerable versions of Java SDK and JRE. For details on upgrading, please visit the following website:

http://www.compaq.com/java/alpha

To fix Compaq Management Agents, it has been suggested that those affected upgrade to the version of the Java Runtime Environment recommended by Microsoft at the following address:

http://www.microsoft.com/java/vm/dl_vm40.htm

SGI has announced that this issue will be resolved in IRIX 6.5.18. Users are advised to upgrade to this version when it becomes available.

Users of IRIX may also manually install updated versions of the JRE and SDK. Full details are available in the referenced advisory. The updated software is available at the following locations:

http://www.sgi.com/products/evaluation/6.x_java_plugin_1.1.1/
http://www.sgi.com/products/evaluation/6.5_java2_1.3.1_02/

Various vendors have released the following fixes which address this issue:


Compaq Integrated Lights-Out on ProLiant DL360 G2

Compaq Remote Insight Lights-Out Edition

Microsoft Virtual Machine 3802 Series

Compaq Insight Manager XE 1.0

Sun JDK (Solaris Reference Release) 1.1.8 _007

Sun JRE (Solaris Reference Release) 1.1.8 _007

Sun JRE (Solaris Production Release) 1.1.8 _13

HP Java JRE/JDK for HP-UX 1.1.8

Sun JRE (Windows Production Release) 1.1.8 _007

Sun JDK (Windows Production Release) 1.1.8 _007

HP Java SDK/RTE for HP-UX PA-RISC 1.2.2

Sun JRE (Windows Production Release) 1.2.2 _010

Sun SDK (Linux Production Release) 1.2.2 _010

Sun SDK (Solaris Production Release) 1.2.2 _10

Sun SDK (Solaris Reference Release) 1.2.2 _010

Compaq Insight Manager XE 1.21

Sun JRE (Windows Production Release) 1.3 .0_02

Sun JRE (Linux Production Release) 1.3 .0_02

HP Java SDK/RTE for HP-UX PA-RISC 1.3

Sun JRE (Windows Production Release) 1.3 .0_04

Sun SDK (Windows Production Release) 1.3 .0_02

Sun SDK (Linux Production Release) 1.3 _02

Sun SDK (Solaris Production Release) 1.3 _02

Sun JRE (Linux Production Release) 1.3 .0_04

Sun JRE (Solaris Production Release) 1.3 .0_02

Compaq Insight Manager XE 2.1

Compaq Insight Manager XE 2.1 b

Compaq Insight Manager XE 2.1 c

Compaq Insight Manager XE 2.2

Compaq Tru64 4.0 f

Compaq Tru64 4.0 g

Compaq Tru64 5.0 a

Compaq Tru64 5.1

Netscape Netscape 6.0 1

Netscape Netscape 6.0

Netscape Communicator 6.1

Compaq Insight Manager 7.0

Compaq OpenVMS 7.2 -2 Alpha

Compaq OpenVMS 7.2 Alpha

Compaq OpenVMS 7.2 -1H1 Alpha

Compaq OpenVMS 7.2 -1H2 Alpha

Compaq OpenVMS 7.2.1 Alpha

Compaq OpenVMS 7.3 Alpha

References

Multiple Vendor Java Virtual Machine Session Hijacking Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report