The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML documentation pages that contain cross-site scripting (XSS) vulnerabilities, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
| Software | From | Fixed in |
|---|---|---|
| oracle / jdk | 1.5.0-update11 | 1.5.0-update11.x |
| oracle / jdk | 1.6.0 | 1.6.0.x |