9.3
CVSSv2

CVE-2008-3103

Published: 09/07/2008 Updated: 11/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unspecified vulnerability in the Java Management Extensions (JMX) management agent in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and previous versions and JDK and JRE 5.0 Update 15 and previous versions, when local monitoring is enabled, allows remote malicious users to "perform unauthorized operations" via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

sun jdk 5.0

sun jre 5.0

sun jre 6

sun jdk 6

sun jre

sun jdk

Vendor Advisories

Synopsis Important: java-150-bea security update Type/Severity Security Advisory: Important Topic java-150-bea as shipped in Red Hat Enterprise Linux 4 Extras and Red HatEnterprise Linux 5 Supplementary, contains security flaws and should not beusedThis update has been rated as having important securit ...
Synopsis Low: java-150-ibm security update Type/Severity Security Advisory: Low Topic Updated java-150-ibm packages that fix several security issues are nowavailable for Red Hat Network Satellite ServerThis update has been rated as having low security impact by the Red HatSecurity Response Team ...
Synopsis Important: java-160-bea security update Type/Severity Security Advisory: Important Topic java-160-bea as shipped in Red Hat Enterprise Linux 4 Extras and Red HatEnterprise Linux 5 Supplementary, contains security flaws and should not beusedThis update has been rated as having important securit ...
Synopsis Moderate: java-150-ibm security update Type/Severity Security Advisory: Moderate Topic Updated java-150-ibm packages that fix a security issue are now availablefor Red Hat Enterprise Linux 4 Extras and 5 SupplementaryThis update has been rated as having moderate security impact by the RedHat S ...
Synopsis Critical: java-160-ibm security update Type/Severity Security Advisory: Critical Topic Updated java-160-ibm packages that fix several security issues are nowavailable for Red Hat Enterprise Linux 4 Extras and Red Hat EnterpriseLinux 5 SupplementaryThis update has been rated as having critical ...

References

CWE-264NVD-CWE-noinfohttp://sunsolve.sun.com/search/document.do?assetkey=1-66-238965-1http://www.securityfocus.com/bid/30146http://secunia.com/advisories/31010http://www.redhat.com/support/errata/RHSA-2008-0594.htmlhttp://secunia.com/advisories/31055http://www.redhat.com/support/errata/RHSA-2008-0595.htmlhttp://www.us-cert.gov/cas/techalerts/TA08-193A.htmlhttp://secunia.com/advisories/31497http://secunia.com/advisories/31600http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.htmlhttp://support.apple.com/kb/HT3178http://support.apple.com/kb/HT3179http://lists.apple.com/archives/security-announce//2008/Sep/msg00008.htmlhttp://secunia.com/advisories/32018http://secunia.com/advisories/32180http://www.vmware.com/security/advisories/VMSA-2008-0016.htmlhttp://secunia.com/advisories/32179http://marc.info/?l=bugtraq&m=122331139823057&w=2http://secunia.com/advisories/32437http://secunia.com/advisories/32436http://www.redhat.com/support/errata/RHSA-2008-0891.htmlhttp://www.securitytracker.com/id?1020458http://secunia.com/advisories/33237http://secunia.com/advisories/33238http://www.redhat.com/support/errata/RHSA-2008-1045.htmlhttp://www.redhat.com/support/errata/RHSA-2008-1044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00009.htmlhttp://secunia.com/advisories/32394http://www.redhat.com/support/errata/RHSA-2008-0906.htmlhttp://secunia.com/advisories/34972https://rhn.redhat.com/errata/RHSA-2009-0466.htmlhttp://support.avaya.com/elmodocs2/security/ASA-2008-428.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-507.htmhttp://support.avaya.com/elmodocs2/security/ASA-2008-509.htmhttp://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://secunia.com/advisories/37386http://www.vupen.com/english/advisories/2008/2056/referenceshttp://www.vupen.com/english/advisories/2008/2740https://exchange.xforce.ibmcloud.com/vulnerabilities/43669https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10920http://www.securityfocus.com/archive/1/497041/100/0/threadedhttps://nvd.nist.govhttps://access.redhat.com/errata/RHSA-2008:1044