Microsoft's Java VM Exposes User Credentials

A flaw in the Java VM could allow a Web site operator to use a visiting user's credentials to gain access to protected data.

ITPro Today

August 21, 2000

1 Min Read
ITPro Today logo

 

Reported August 21, 2000 by Microsoft

VERSIONS AFFECTED

  • Microsoft Java VM Series 2000, 3100, 3200, 3300 (installed with Internet Explorer 4.x and 5.x)

DESCRIPTION

By design, the browser-based Java VM runs untrusted Java applets within a security sandbox that restricts the applet's access to user's system. However, a flaw in the sandbox design could allow a Web site operator to use a visiting user's credentials to gain access to protected data.  

VENDOR RESPONSE

Microsoft has released FAQ #FQ00-059, Support Online article Q271752, and patches for the affect versions.

To determine your Java VM version open a command window and enter the command "jview", which will display the version number.

According to Microsoft's bulletin,

CREDIT
Discovered by Microsoft

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like