The Sun Java Plugin capability in Java 2 Runtime Environment...
Vulnerability Description
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-1029
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.idefense.com/application/poi/display?id=158&type=vulnerabilities
- http://jouko.iki.fi/adv/javaplugin.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5674
- http://lists.apple.com/archives/security-announce/2005/Feb/msg00000.html
- http://rpmfind.net/linux/RPM/suse/updates/9.3/i386/rpm/i586/java-1_4_2-sun-src-1.4.2.08-0.1.i586.html
- http://secunia.com/advisories/13271
- http://secunia.com/advisories/29035
- http://securityreason.com/securityalert/61
- http://www.securityfocus.com/bid/12317
- http://www.vupen.com/english/advisories/2008/0599
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18188
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101523-1
- http://www.kb.cert.org/vuls/id/760344
- http://www-1.ibm.com/support/docview.wss?uid=swg21257249
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-57591-1
More from hp
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.