CVE-2010-0886
Description
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6 Update 10 through 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
JAVA Web Start - Arbitrary Command-Line Injection
Sun Java Web Start Plugin - Command Line Argument Injection (Metasploit)
Java Deployment Toolkit - Performs Insufficient Validation of Parameters
Sun Java - Web Start Plugin Command Line Argument Injection (Metasploit)
Metasploit modules
References
- http://lists.apple.com/archives/security-announce/2010//May/msg00001.html
- http://lists.apple.com/archives/security-announce/2010//May/msg00002.html
- http://marc.info/?l=bugtraq&m=134254866602253&w=2
- http://secunia.com/advisories/39819
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-279590-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022294.1-1
- http://support.apple.com/kb/HT4170
- http://support.apple.com/kb/HT4171
- http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0886.html
- http://www.securityfocus.com/archive/1/516397/100/0/threaded
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html
- http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html
- http://www.vupen.com/english/advisories/2010/1191
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14216
- http://lists.apple.com/archives/security-announce/2010//May/msg00001.html
- http://lists.apple.com/archives/security-announce/2010//May/msg00002.html
- http://marc.info/?l=bugtraq&m=134254866602253&w=2
- http://secunia.com/advisories/39819
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-279590-1
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1022294.1-1
- http://support.apple.com/kb/HT4170
- http://support.apple.com/kb/HT4171
- http://www.oracle.com/technology/deploy/security/alerts/alert-cve-2010-0886.html
- http://www.securityfocus.com/archive/1/516397/100/0/threaded
- http://www.vmware.com/security/advisories/VMSA-2011-0003.html
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.