CVE-2009-2476

Sun Java SE 6 <Update 15 - Privilege Escalation

Title source: llm

Description

The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.

Scores

EPSS 0.0172
EPSS Percentile 82.1%

Classification

CWE
CWE-264
Status draft

Affected Products (2)

sun/java_se < 6
sun/openjdk

Timeline

Published Aug 10, 2009
Tracked Since Feb 18, 2026