Oracle Java SE and Java for Business contain a flaw related to the 'com.sun.jnlp.BasicServiceImpl' class. The issue is triggered when a remote attacker exploits Web Start's retrieval of security policies. This may allow an attacker to execute arbitrary code.
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Patch / RCS
Exploit:
Exploit Private,
Exploit Commercial
Disclosure:
Vendor Verified,
Coordinated Disclosure
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Sun has released a patch to address this vulnerability.