Sun Microsystems JRE HTTP Property Access Vulnerability

BID:7851

Info

Sun Microsystems JRE HTTP Property Access Vulnerability

Bugtraq ID: 7851
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Jun 06 2003 12:00AM
Updated: Jun 06 2003 12:00AM
Credit: Discovery of this vulnerability has been credited to Harmen van der Wal.
Vulnerable: Sun SDK (Windows Production Release) 1.3.1 _02
Sun SDK (Windows Production Release) 1.3.1 _01a
Sun SDK (Windows Production Release) 1.3 .0_05
Sun SDK (Windows Production Release) 1.3 .0_02
Sun SDK (Windows Production Release) 1.2.2 _011
Sun SDK (Windows Production Release) 1.2.2 _010
Sun SDK (Solaris Production Release) 1.3.1 _03
Sun SDK (Solaris Production Release) 1.3.1 _02
Sun SDK (Solaris Production Release) 1.3.1 _01
Sun SDK (Solaris Production Release) 1.3 _05
Sun SDK (Solaris Production Release) 1.3 _02
Sun SDK (Solaris Production Release) 1.3
Sun SDK (Solaris Production Release) 1.2.2 _10
Sun SDK (Reference Release) 1.2.2 _010
Sun SDK (Linux Production Release) 1.3.1 _02
Sun SDK (Linux Production Release) 1.3.1 _01
Sun SDK (Linux Production Release) 1.3 _05
Sun SDK (Linux Production Release) 1.3 _02
Sun SDK (Linux Production Release) 1.2.2 _011
Sun SDK (Linux Production Release) 1.2.2 _010
Sun JRE (Windows Production Release) 1.3.1 _02
Sun JRE (Windows Production Release) 1.3 .0_05
Sun JRE (Windows Production Release) 1.3 .0_04
Sun JRE (Windows Production Release) 1.3 .0_02
Sun JRE (Windows Production Release) 1.2.2 _011
Sun JRE (Windows Production Release) 1.2.2 _010
Sun JRE (Solaris Production Release) 1.3.1 _02
Sun JRE (Solaris Production Release) 1.3.1 _01
Sun JRE (Solaris Production Release) 1.3 .0_05
Sun JRE (Solaris Production Release) 1.3 .0_02
Sun JRE (Solaris Production Release) 1.2.2 _011
Sun JRE (Solaris Production Release) 1.2.2 _010
Sun JRE (Solaris Production Release) 1.2.2
Sun JRE (Reference Release) 1.2.2 _010
Sun JRE (Linux Production Release) 1.3.1 _02
Sun JRE (Linux Production Release) 1.3.1 _01
Sun JRE (Linux Production Release) 1.3.1
Sun JRE (Linux Production Release) 1.3 .0_05
Sun JRE (Linux Production Release) 1.3 .0_04
Sun JRE (Linux Production Release) 1.3 .0_03
Sun JRE (Linux Production Release) 1.3 .0_02
Sun JRE (Linux Production Release) 1.3 .0_01
Sun JRE (Linux Production Release) 1.3 .0
Sun JRE (Linux Production Release) 1.2.2 _011
Sun JRE (Linux Production Release) 1.2.2 _010
Sun JRE (Linux Production Release) 1.2.2 _007
Sun JRE (Linux Production Release) 1.2.2 _006
Sun JRE (Linux Production Release) 1.2.2 _005
- Debian Linux 2.2
- Mandriva Linux Mandrake 7.2
- Redhat Linux 7.0
- SuSE Linux 7.0
Sun JRE (Linux Production Release) 1.2.2 _004
Sun JRE (Linux Production Release) 1.2.2 _003
Sun JRE (Linux Production Release) 1.2.2
Sun JDK (Windows Production Release) 1.1.8 _008
Sun JDK (Windows Production Release) 1.1.8 _007
Sun JDK (Windows Production Release) 1.1.8 _005
Sun JDK (Windows Production Release) 1.1.8 _002
Sun JDK (Solaris Reference Release) 1.1.8 _008
Sun JDK (Solaris Reference Release) 1.1.8 _007
Sun JDK (Solaris Reference Release) 1.1.8 _005
Sun JDK (Solaris Reference Release) 1.1.8 _002
Sun JDK (Solaris Reference Release) 1.1.8
Sun JDK (Solaris Production Release) 1.1.8 _14
Sun JDK (Solaris Production Release) 1.1.8 _13
Sun JDK (Solaris Production Release) 1.1.8 _12
Sun JDK (Solaris Production Release) 1.1.8 _11
+ Sun Solaris 8_x86
+ Sun Solaris 8_sparc
+ Sun Solaris 7.0_x86
+ Sun Solaris 7.0
+ Sun Solaris 2.6_x86
+ Sun Solaris 2.6
Sun JDK (Solaris Production Release) 1.1.8 _10
Sun JDK (Solaris Production Release) 1.1.8 _009
Sun JDK (Solaris Production Release) 1.1.8
Not Vulnerable: Sun SDK (Windows Production Release) 1.3.1 _03
Sun SDK (Windows Production Release) 1.2.2 _012
Sun SDK (Solaris Production Release) 1.2.2 _12
Sun SDK (Reference Release) 1.2.2 _012
Sun SDK (Linux Production Release) 1.3.1 _03
Sun SDK (Linux Production Release) 1.2.2 _12
Sun JRE (Windows Production Release) 1.3.1 _03
+ Macromedia ColdFusion Server MX Professional
+ Macromedia ColdFusion Server MX Enterprise
+ Macromedia ColdFusion Server MX Developer
Sun JRE (Windows Production Release) 1.2.2 _12
Sun JRE (Solaris Reference Release) 1.2.2 _012
Sun JRE (Solaris Production Release) 1.3.1 _03
+ Macromedia ColdFusion Server MX Professional
+ Macromedia ColdFusion Server MX Enterprise
+ Macromedia ColdFusion Server MX Developer
Sun JRE (Solaris Production Release) 1.2.2 _012
Sun JRE (Linux Production Release) 1.3.1 _03
+ Macromedia ColdFusion Server MX Professional
+ Macromedia ColdFusion Server MX Enterprise
+ Macromedia ColdFusion Server MX Developer
Sun JRE (Linux Production Release) 1.2.2 _12
Sun JDK (Windows Production Release) 1.1.8 _009
Sun JDK (Solaris Production Release) 1.1.8 _15
Sun JDK (Reference Release) 1.1.8 _009

Discussion

Sun Microsystems JRE HTTP Property Access Vulnerability

Sun Microsystems has reported a vulnerability in the Java Runtime Environment (JRE). It is possible for an untrusted Java applet to gain access to properties of HTTP requests. This could result in disclosure of sensitive or private information.

It should be noted that SDK and JRE 1.4.0 and later releases for Windows, Linux, and Solaris are not affected by this issue.

Exploit / POC

Sun Microsystems JRE HTTP Property Access Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Sun Microsystems JRE HTTP Property Access Vulnerability

Solution:
This issue has been addressed in the following releases:

Windows Production Releases

SDK and JRE 1.3.1_03 and later
SDK and JRE 1.2.2_012 and later
JDK 1.1.8_009 and later

Solaris Operating Environment (OE) Reference Releases

SDK and JRE 1.2.2_012 and later
JDK 1.1.8_009 and later

Solaris OE Production Releases

SDK and JRE 1.3.1_03 and later
SDK and JRE 1.2.2_12 and later
JDK 1.1.8_15 and later

Linux Production Releases

SDK and JRE 1.3.1_03 and later
SDK and JRE 1.2.2_012 and later

These upgrades are available at:

http://java.sun.com/j2se/

References

Sun Microsystems JRE HTTP Property Access Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report