Junglewise Threat Intelligence

CVE-2010-0840: Oracle JRE Unspecified Vulnerability

CVE-2010-0840 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-05-25

Technologies: Oracle Java SE JDK, Oracle Java Runtime Environment (JRE). Vendors: Oracle.

Executive brief

An unspecified vulnerability in the Oracle Java Runtime Environment (JRE) allows remote attackers to execute arbitrary code via improper checks when executing privileged methods. This flaw, known as the Trusted Methods Chaining vulnerability, enables attackers to bypass sandbox restrictions and affect confidentiality, integrity, and availability.

Affected products

  • Oracle Java SE JDK and JRE 6 Update 18 and earlier
  • Oracle Java SE JDK 5.0 Update 23 and earlier
  • Oracle Java SE SDK 1.4.2_25 and earlier
  • Oracle Java for Business JDK and JRE 6 Update 18 and earlier, 5.0 Update 23 and earlier
  • Oracle Java for Business SDK and JRE 1.4.2_25 and earlier

Timeline

  • 2010-03-30: advisory: Initial disclosure in Oracle March 2010 Critical Patch Update (CPU)
  • 2022-05-25: disclosed: NVD publication date
  • exploited: Listed in CISA Known Exploited Vulnerabilities (KEV) Catalog

Related threats