CVE-2009-2689

Sun Java SE <5.0U20 & 6 < U15 - Privilege Escalation

Title source: llm

Description

JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application.

Scores

EPSS 0.0751
EPSS Percentile 91.6%

Classification

CWE
CWE-264
Status draft

Affected Products (3)

sun/java_se < 5.0
sun/java_se < 6
sun/openjdk

Timeline

Published Aug 10, 2009
Tracked Since Feb 18, 2026