CVE-2010-0092
Description
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Oracle Java SE 6 Update 18 and 5.0 Update 23 contain an unspecified JRE vulnerability that can lead to complete confidentiality, integrity, and availability compromise via remote attack.
Vulnerability
CVE-2010-0092 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE and Java for Business. Affected versions are Java SE 6 Update 18 and Java SE 5.0 Update 23 [1][2][3][4]. The vendor description notes that the vulnerability can be exploited via unknown vectors, implying a remote attack vector without requiring prior authentication.
Exploitation
Neither the official description nor the available references provide concrete exploitation steps or prerequisites. The vulnerability is listed among many in bundled security advisories from VMware, HP, and Ubuntu, but no public exploit code or attack scenario is described [1][2][3][4].
Impact
If successfully exploited, the vulnerability could compromise all three security pillars: confidentiality, integrity, and availability. The exact scope of the compromise (e.g., arbitrary code execution, information disclosure, denial of service) is not detailed, but the impact is rated as potentially complete [1][2][3][4].
Mitigation
The affected Java versions are no longer supported by Oracle. Users should upgrade to Java SE 6 Update 19 or later, or Java SE 5.0 Update 24 or later, as recommended by the Ubuntu security notice and HP-UX bulletins [3][4]. VMware and HP advisories also include updates that address this CVE [1][2]. No workaround is documented for this vulnerability.
- Support Content Notification - Support Portal - Broadcom support portal
- '[security bulletin] HPSBMU02799 SSRT100867 rev.1 - HP Network Node Manager i (NNMi) v9.0x Running JD'
- USN-923-1: OpenJDK vulnerabilities | Ubuntu security notices | Ubuntu
- '[security bulletin] HPSBUX02524 SSRT100089 rev.1 - HP-UX Running Java, Remote Execution of Arbitrary'
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
83cpe:2.3:a:sun:jdk:1.5.0:*:*:*:*:*:*:*+ 40 more
- cpe:2.3:a:sun:jdk:1.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update1:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update10:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update11:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update12:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update13:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update14:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update15:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update16:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update17:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update18:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update19:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update2:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update20:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update21:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update3:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update4:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update5:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update6:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update7:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update8:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.5.0:update9:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update1:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update_10:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update_11:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update_12:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update_13:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update_14:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update_15:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update_16:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update_17:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update1_b06:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update2:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update_3:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update_4:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update_5:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update_6:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:1.6.0:update_7:*:*:*:*:*:*
- cpe:2.3:a:sun:jdk:*:update_18:*:*:*:*:*:*range: <=1.6.0
- cpe:2.3:a:sun:jdk:*:update23:*:*:*:*:*:*range: <=1.5.0
cpe:2.3:a:sun:jre:1.5.0:*:*:*:*:*:*:*+ 39 more
- cpe:2.3:a:sun:jre:1.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update1:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update10:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update11:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update12:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update13:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update14:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update15:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update16:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update17:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update18:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update19:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update2:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update20:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update21:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update3:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update4:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update5:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update6:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update7:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update8:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.5.0:update9:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_12:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_13:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_14:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_15:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_16:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_17:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_2:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_3:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_4:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_5:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_6:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:1.6.0:update_7:*:*:*:*:*:*
- cpe:2.3:a:sun:jre:*:update_18:*:*:*:*:*:*range: <=1.6.0
- cpe:2.3:a:sun:jre:*:update23:*:*:*:*:*:*range: <=1.5.0
- Range: 6 Update 18, 5.0 Update 23
- Range: 6 Update 18, 5.0 Update 23
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
32- secunia.com/advisories/39292nvdVendor Advisory
- secunia.com/advisories/39317nvdVendor Advisory
- secunia.com/advisories/39659nvdVendor Advisory
- secunia.com/advisories/39819nvdVendor Advisory
- secunia.com/advisories/40545nvdVendor Advisory
- secunia.com/advisories/43308nvdVendor Advisory
- www.vupen.com/english/advisories/2010/1107nvdVendor Advisory
- www.vupen.com/english/advisories/2010/1191nvdVendor Advisory
- www.vupen.com/english/advisories/2010/1454nvdVendor Advisory
- www.vupen.com/english/advisories/2010/1793nvdVendor Advisory
- itrc.hp.com/service/cki/docDisplay.donvd
- lists.apple.com/archives/security-announce/2010//May/msg00001.htmlnvd
- lists.apple.com/archives/security-announce/2010//May/msg00002.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.htmlnvd
- marc.infonvd
- marc.infonvd
- support.apple.com/kb/HT4170nvd
- support.apple.com/kb/HT4171nvd
- ubuntu.com/usn/usn-923-1nvd
- www.mandriva.com/security/advisoriesnvd
- www.oracle.com/technetwork/topics/security/javacpumar2010-083341.htmlnvd
- www.redhat.com/support/errata/RHSA-2010-0337.htmlnvd
- www.redhat.com/support/errata/RHSA-2010-0338.htmlnvd
- www.redhat.com/support/errata/RHSA-2010-0339.htmlnvd
- www.redhat.com/support/errata/RHSA-2010-0383.htmlnvd
- www.redhat.com/support/errata/RHSA-2010-0471.htmlnvd
- www.securityfocus.com/archive/1/516397/100/0/threadednvd
- www.vmware.com/security/advisories/VMSA-2011-0003.htmlnvd
- www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.htmlnvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10057nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14210nvd
News mentions
0No linked articles in our index yet.