Security Advisory

CVE-2009-2476

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2009-08-10 18:00:00
Last updated 2024-08-07 05:52:15
Assigner redhat
State PUBLISHED

Description

The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.