CVE-2010-0840

Confirmed PUBLISHED

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and...

Oracle · Java SE
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."

metasploit java cisa
CVE Published
Apr 01, 2010
Exploitation Reported
May 25, 2022
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • APPLE-SA-2010-05-18-1 lists.apple.com · Vendor Advisory http://lists.apple.com/archives/security-announce/2010//May/msg00001....
  • HPSBMU02799 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=134254866602253&w=2
  • RHSA-2010:0383 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0383.html
  • RHSA-2010:0338 redhat.com · Vendor Advisory http://www.redhat.com/support/errata/RHSA-2010-0338.html
  • APPLE-SA-2010-05-18-2 lists.apple.com · Vendor Advisory http://lists.apple.com/archives/security-announce/2010//May/msg00002....
Show 35 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.