CVE-2009-2476
10.08.2009, 18:30
The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.Enginsight
Vendor | Product | Version |
---|---|---|
sun | java_se | 𝑥 ≤ 6 |
sun | openjdk | * |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
java |
| ||||||||||||||
openjdk-6 |
| ||||||||||||||
sun-java5 |
| ||||||||||||||
sun-java6 |
|
Common Weakness Enumeration
References