CVE-2007-3504

JDK and JRE < 1.5.0 - Path Traversal via PersistenceService

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execute arbitrary code by overwriting a .java.policy file.

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35169
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2384
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018328
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37755
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.html
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/4224
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25823
Patch vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102957-1
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28115
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/472673/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24695

Scores

EPSS 0.0516
EPSS Percentile 90.0%

Details

CWE
CWE-22
Status published
Products (4)
sun/jdk < 1.5.0
sun/jre < 1.4.2
sun/jre < 1.5.0
sun/sdk < 1.4.2_13
Published Jun 30, 2007
Tracked Since Feb 18, 2026