CVE-2008-3115
Description
Secure Static Versioning in Sun Java JDK and JRE 6 Update 6 and earlier, and 5.0 Update 6 through 15, does not properly prevent execution of applets on older JRE releases, which might allow remote attackers to exploit vulnerabilities in these older releases.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Secure Static Versioning in Sun Java JDK/JRE improperly allows applets to execute on older JRE releases, enabling exploitation of known vulnerabilities.
Vulnerability
The Secure Static Versioning mechanism in Sun Java JDK and JRE 6 Update 6 and earlier, and 5.0 Update 6 through 15, does not properly prevent execution of applets on older JRE releases [1][2]. This allows a Java applet to run on a less recent version of the JRE than intended, bypassing the static version check and potentially exposing known vulnerabilities in the older release.
Exploitation
An attacker can host a malicious webpage containing a Java applet that exploits this flaw. When a user visits the page with a vulnerable Java plugin enabled, the applet can be executed on an older, vulnerable JRE version, allowing the attacker to leverage security issues present in that older release [1].
Impact
Successful exploitation enables the attacker to execute arbitrary code within the context of the older JRE, potentially leading to system compromise, information disclosure, or other impacts depending on the specific vulnerabilities in the targeted older JRE version [2].
Mitigation
Sun released fixes in later versions: Java 6 Update 7 and later, and Java 5.0 Update 16 and later. VMware products, including VirtualCenter 2.5 Update 3, also addressed this issue by updating the bundled Java JRE packages [1][2]. Users should update to the latest supported Java version and apply vendor-specific patches.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
34cpe:2.3:a:sun:jdk:5.0:update_10:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:sun:jdk:5.0:update_10:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_11:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_12:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_13:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_14:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_15:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_6:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_7:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_8:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:5.0:update_9:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:6:update_1:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:6:update_2:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:6:update_3:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:6:update_4:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:6:update_5:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:*:update_6:*:*:*:*:*:*range: <=6
cpe:2.3:a:sun:jre:5.0:update_10:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:sun:jre:5.0:update_10:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_11:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_12:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_13:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_14:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_15:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_6:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_7:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_8:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:5.0:update_9:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:6:update_1:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:6:update_2:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:6:update_3:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:6:update_4:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:6:update_5:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:*:update_6:*:*:*:*:*:*range: <=6
- Range: <=6u6, >=5.0u6 <=5.0u15
- Range: <=6u6, >=5.0u6 <=5.0u15
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
21- sunsolve.sun.com/search/document.donvdPatch
- secunia.com/advisories/31010nvdVendor Advisory
- www.us-cert.gov/cas/techalerts/TA08-193A.htmlnvdUS Government Resource
- lists.apple.com/archives/security-announce//2008/Sep/msg00008.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2008-08/msg00005.htmlnvd
- marc.infonvd
- secunia.com/advisories/31600nvd
- secunia.com/advisories/32018nvd
- secunia.com/advisories/32179nvd
- secunia.com/advisories/32180nvd
- secunia.com/advisories/37386nvd
- security.gentoo.org/glsa/glsa-200911-02.xmlnvd
- support.apple.com/kb/HT3178nvd
- support.apple.com/kb/HT3179nvd
- www.securityfocus.com/archive/1/497041/100/0/threadednvd
- www.securityfocus.com/bid/30142nvd
- www.securitytracker.com/idnvd
- www.vmware.com/security/advisories/VMSA-2008-0016.htmlnvd
- www.vupen.com/english/advisories/2008/2056/referencesnvd
- www.vupen.com/english/advisories/2008/2740nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/43665nvd
News mentions
0No linked articles in our index yet.