Finjan SurfinGate Java Applet Analyzer Bypass Vulnerability

BID:6704

Info

Finjan SurfinGate Java Applet Analyzer Bypass Vulnerability

Bugtraq ID: 6704
Class: Configuration Error
CVE:
Remote: Yes
Local: No
Published: Jan 28 2003 12:00AM
Updated: Jan 28 2003 12:00AM
Credit: Discovery of this vulnerability is credited to Compass Security.
Vulnerable: Finjan Software SurfinGate 7.0
Finjan Software SurfinGate 6.0 5
Finjan Software SurfinGate 6.0 1
Finjan Software SurfinGate 6.0
Finjan Software SurfinGate 5.6
Not Vulnerable:

Discussion

Finjan SurfinGate Java Applet Analyzer Bypass Vulnerability

The Finjan SurfinGate Java applet analyzer does not properly detect the use of the Java Reflection API. As a result, this API may be used to call methods and classes that may otherwise be restricted.

A malicious Java applet may use this technique to bypass the Finjan SurfinGate filter. End users may not be protected from malicious Java applets as a result.

It should be noted that this issue exists when the "Load Other Java Classes" feature is enabled (which it is by default). Disabling this feature will mitigate this issue by may cause Java applets to be blocked too aggressively. Even with this feature enabled, loaded Java classes will be scanned, which may block some malicious behavior.

Exploit / POC

Finjan SurfinGate Java Applet Analyzer Bypass Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Finjan SurfinGate Java Applet Analyzer Bypass Vulnerability

Solution:
The vendor has announced this issue and announced that it will be addressed more completely in a future release of SurfinGate.

Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

References

Finjan SurfinGate Java Applet Analyzer Bypass Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report