Unrated severityNVD Advisory· Published Oct 6, 2007· Updated Jun 16, 2026
CVE-2007-5238
CVE-2007-5238
Description
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka "three vulnerabilities."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
65cpe:2.3:a:sun:jdk:1.5.0:update1:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:sun:jdk:1.5.0:update1:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update10:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update11:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update12:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update2:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update3:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update4:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update5:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update7:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update8:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update9:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update1:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update2:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.3.0:*:*:*:*:*:*:*+ 34 more
- cpe:2.3:a:sun:jre:1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.3.0:update5:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.3.1:update1:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.3.1:update16:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.3.1:update18:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.3.1:update19:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.3.1:update1a:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.3.1:update20:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.1:update3:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_1:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_10:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_11:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_12:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_13:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_14:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_15:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_3:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_8:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.4.2_9:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update1:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update10:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update11:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update12:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update2:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update3:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update4:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update5:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update6:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update7:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update8:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update9:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_2:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.3.1_01:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:sun:sdk:1.3.1_01:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.3.1_01a:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.3.1_16:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.3.1_18:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.3.1_19:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.3.1_20:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_03:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_08:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_09:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_10:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_11:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_12:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_13:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_14:*:*:*:*:*:*:*
- cpe:2.3:a:sun:sdk:1.4.2_15:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
33- secunia.com/advisories/27693nvdPatch
- secunia.com/advisories/27716nvdPatch
- sunsolve.sun.com/search/document.donvdPatch
- dev2dev.bea.com/pub/advisory/272nvd
- h20000.www2.hp.com/bizsupport/TechSupport/Document.jspnvd
- lists.opensuse.org/opensuse-security-announce/2008-04/msg00010.htmlnvd
- secunia.com/advisories/27206nvd
- secunia.com/advisories/27261nvd
- secunia.com/advisories/27804nvd
- secunia.com/advisories/28777nvd
- secunia.com/advisories/28880nvd
- secunia.com/advisories/29042nvd
- secunia.com/advisories/29858nvd
- secunia.com/advisories/29897nvd
- secunia.com/advisories/30676nvd
- secunia.com/advisories/30780nvd
- security.gentoo.org/glsa/glsa-200804-28.xmlnvd
- support.novell.com/techcenter/psdb/0c36b6416afc3868b8b1b9012955e323.htmlnvd
- www.gentoo.org/security/en/glsa/glsa-200804-20.xmlnvd
- www.gentoo.org/security/en/glsa/glsa-200806-11.xmlnvd
- www.novell.com/linux/security/advisories/2007_55_java.htmlnvd
- www.redhat.com/support/errata/RHSA-2007-0963.htmlnvd
- www.redhat.com/support/errata/RHSA-2007-1041.htmlnvd
- www.redhat.com/support/errata/RHSA-2008-0132.htmlnvd
- www.securityfocus.com/archive/1/482926/100/0/threadednvd
- www.securityfocus.com/bid/25920nvd
- www.securitytracker.com/idnvd
- www.vmware.com/security/advisories/VMSA-2008-0010.htmlnvd
- www.vupen.com/english/advisories/2007/3895nvd
- www.vupen.com/english/advisories/2008/0609nvd
- www.vupen.com/english/advisories/2008/1856/referencesnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/36946nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11592nvd
News mentions
0No linked articles in our index yet.