Vulnerability tracking firm Secunia has rated the flaw "highly critical," meaning it can be exploited without user interaction, but there are no known exploits in the wild.
The flaw exists in DJK and JRE Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier and SDK and JRE 1.3.1_18 and earlier, and was first reported to Sun in June, according to 3Com's Zero Day Initiative.
Sun released a patch for the flaw on Tuesday, according to a company security advisory.
Click here to email Online Editor Frank Washkuch Jr.

iTnews Benchmark Security Awards 2025
Digital Leadership Day Federal
Government Cyber Security Showcase Federal
Government Innovation Showcase Federal
Digital NSW 2025 Showcase



