SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#931684

Sun Java Management Extensions privilege escalation vulnerability

Overview

A vulnerability in the Sun Java Management Extensions API may allow a remote attacker to execute arbitrary code.

I. Description

According to Sun Microsystems:

    Java Management Extensions (JMX) technology provides the tools for building distributed, Web-based, modular and dynamic solutions for managing and monitoring devices, applications, and service-driven networks.


An unspecified vulnerability in the JMX API may allow an untrusted Java applet to execute elevated privileges. For more information, please refer to Sun Alert 102017.

II. Impact

A remote attacker may be able to execute arbitrary code.

III. Solution

Upgrade Java

Sun addressed this issue in the Java Development Kit (JDK) and the Java Runtime Environment (JRE) 5.0 Update 4.

Do not access Java Applets from untrusted sources

Attackers must deliver a malicious Java applet to a vulnerable system in order to take advantage of this vulnerability. By only accessing Java applets from known and trusted sources the chances of exploitation are reduced.

Disable Java in web browser

Java applets are commonly executed within a web browser. Disabling Java within the web browser may prevent an attacker from delivering a malicious applet to a vulnerable system.

Systems Affected

VendorStatusDate NotifiedDate Updated
Sun Microsystems, Inc.Vulnerable30-Nov-2005

References


http://secunia.com/advisories/17748/
http://java.sun.com/products/JavaManagement/
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102017-1

Credit

This vulnerability was reported by Sun Microsystems. Sun credits Adam Gowdiak with providing information regarding this issue.

This document was written by Jeff Gennari.

Other Information

Date Public:2005-11-28
Date First Published:2005-12-02
Date Last Updated:2006-01-12
CERT Advisory: 
CVE-ID(s):CVE-2005-3904
NVD-ID(s):CVE-2005-3904
US-CERT Technical Alerts: 
Metric:9.00
Document Revision:33

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2005 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader