[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-4820Date: (C)2013-01-11   (M)2024-04-30


Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, when running under a security manager, allows remote attackers to gain privileges by modifying or removing the security manager via vectors related to "insecure use of the java.lang.reflect.Method invoke() method."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://seclists.org/bugtraq/2012/Sep/38
SECUNIA-51326
SECUNIA-51327
SECUNIA-51328
SECUNIA-51393
SECUNIA-51634
BID-55495
IV29654
RHSA-2012:1465
RHSA-2012:1466
RHSA-2012:1467
RHSA-2013:1455
RHSA-2013:1456
http://www-01.ibm.com/support/docview.wss?uid=swg21615705
http://www-01.ibm.com/support/docview.wss?uid=swg21615800
http://www-01.ibm.com/support/docview.wss?uid=swg21616490
http://www-01.ibm.com/support/docview.wss?uid=swg21616594
http://www-01.ibm.com/support/docview.wss?uid=swg21616616
http://www-01.ibm.com/support/docview.wss?uid=swg21616617
http://www-01.ibm.com/support/docview.wss?uid=swg21616652
http://www-01.ibm.com/support/docview.wss?uid=swg21616708
http://www-01.ibm.com/support/docview.wss?uid=swg21621154
http://www-01.ibm.com/support/docview.wss?uid=swg21631786
https://www-304.ibm.com/support/docview.wss?uid=swg21616546
ibm-java-invoke-code-execution(78764)

CPE    124
cpe:/a:ibm:smart_analytics_system_5600_software:9.7
cpe:/a:ibm:tivoli_monitoring:6.2.1.0
cpe:/a:ibm:tivoli_monitoring:6.2.1.1
cpe:/a:ibm:tivoli_monitoring:6.2.1.2
...
OVAL    3
oval:org.secpod.oval:def:505581
oval:org.secpod.oval:def:505539
oval:org.secpod.oval:def:505399

© SecPod Technologies