CVE-2011-0902 describes multiple untrusted search path vulnerabilities in the Java Service of Sun Microsystems SunScreen Firewall on SunOS 5.9. A local attacker can exploit this by manipulating the PATH or LD_LIBRARY_PATH environment variables to execute arbitrary code. With a CVSS score of 6.9, this vulnerability has high impact potential (C:C/I:C/A:C) but requires local access and medium attack complexity (AV:L/AC:M). While not actively exploited in the wild (KEV: No), a public exploit (EDB-16041) exists for privilege escalation, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:oracle:sun_microsystems_sunscreen_firewall:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.