| [Japanese] | 
| JVNDB-2011-000034 | 
| Java Web Start may insecurely load settings files | 
|
| 
 
Java Web Start provided Oracle may use unsafe methods for determining how to load settings files.
 Java Web Start is tool to distribute Java applications over the web and is contained in Java applications such as JRE (Java Runtime Environment) Java Web Start contains an issue with the file search path, which may insecurely load settings files.
 
 Hisashi Kojima of Fujitsu Laboratories, Ltd. reported this vulnerability to IPA.
 JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.
 | 
|
| 
 
  CVSS V2 Severity:Base Metrics 6.8 (Medium) [IPA Score]
 
    Access Vector: NetworkAccess Complexity: MediumAuthentication: NoneConfidentiality Impact: PartialIntegrity Impact: PartialAvailability Impact: Partial 
  
 | 
|
| 
 
	
 | 
| 
 
	Sun Microsystems, Inc.
	
		Hewlett-Packard Development Company, L.PJDK 6 Update 25 and earlier for WindowsJRE 6 Update 25 and earlier for Windows 
		HP Systems Insight Manager prior to v7.0 | 
| 
 
	
 | 
|
| 
 
An attacker may execute arbitrary code with the privilege of the running application.
 | 
|
| 
 
[Update the software]Update to the latest version according to the information provided by the developer.
 | 
|
| 
 
	Oracle Corporation
	
	Hewlett-Packard Development Company, L.P
	
 | 
|
| 
 
	No Mapping(CWE-Other) [IPA Evaluation] | 
|
| 
 
	CVE-2011-0786  | 
|
| 
 
	JVN : JVN#09206238 National Vulnerability Database (NVD) : CVE-2011-0786 IPA SECURITY ALERTS : Security Alert for Multiple Vulnerabilities in Java Web Start  | 
|
| 
 
	[2011/06/10]Web page published
 [2013/03/26]
 Affected Products : Product was added (HPSBMU02769 SSRT100846)
 Vendor Information : Content was added (HPSBMU02769 SSRT100846)
 
 |