[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-3009Date: (C)2013-07-26   (M)2024-04-30


The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 improperly exposes the invoke method of the java.lang.reflect.Method class, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to the AccessController doPrivileged block.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
http://seclists.org/fulldisclosure/2016/Apr/3
http://seclists.org/fulldisclosure/2016/Apr/20
SECUNIA-54154
IV44792
IX90118
PM91727
RHSA-2013:1059
RHSA-2013:1060
RHSA-2013:1081
SUSE-SU-2013:1255
SUSE-SU-2013:1256
SUSE-SU-2013:1257
SUSE-SU-2013:1263
SUSE-SU-2013:1264
SUSE-SU-2013:1293
SUSE-SU-2013:1305
http://www-01.ibm.com/support/docview.wss?uid=swg21642336
http://www-01.ibm.com/support/docview.wss?uid=swg21644197
http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_July_2013
http://www.security-explorations.com/materials/SE-2012-01-IBM-2.pdf
http://www.security-explorations.com/materials/SE-2012-01-IBM-4.pdf
ibm-java-cve20133009(84150)

CPE    62
cpe:/a:ibm:java:5.0.16.2
cpe:/a:ibm:java:6.0.8.1
cpe:/a:ibm:java:6.0.8.0
cpe:/a:ibm:java:5.0.12.3
...
OVAL    4
oval:org.secpod.oval:def:400763
oval:org.secpod.oval:def:505282
oval:org.secpod.oval:def:505552
oval:org.secpod.oval:def:505437
...

© SecPod Technologies