Lucene search

K
cveIbmCVE-2013-3009
HistoryJul 23, 2013 - 11:03 a.m.

CVE-2013-3009

2013-07-2311:03:19
ibm
web.nvd.nist.gov
46
2
cve-2013-3009
ibm java
remote code execution
security bypass
accesscontrol
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0.032

Percentile

91.2%

The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 improperly exposes the invoke method of the java.lang.reflect.Method class, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to the AccessController doPrivileged block.

Affected configurations

Nvd
Node
ibmjavaMatch1.4.2
OR
ibmjavaMatch1.4.2.13
OR
ibmjavaMatch1.4.2.13.1
OR
ibmjavaMatch1.4.2.13.2
OR
ibmjavaMatch1.4.2.13.3
OR
ibmjavaMatch1.4.2.13.4
OR
ibmjavaMatch1.4.2.13.5
OR
ibmjavaMatch1.4.2.13.6
OR
ibmjavaMatch1.4.2.13.7
OR
ibmjavaMatch1.4.2.13.8
OR
ibmjavaMatch1.4.2.13.9
OR
ibmjavaMatch1.4.2.13.10
OR
ibmjavaMatch1.4.2.13.11
OR
ibmjavaMatch1.4.2.13.12
OR
ibmjavaMatch1.4.2.13.13
OR
ibmjavaMatch1.4.2.13.14
OR
ibmjavaMatch1.4.2.13.15
OR
ibmjavaMatch1.4.2.13.16
OR
ibmjavaMatch1.4.2.13.17
Node
ibmjavaMatch7.0.0.0
OR
ibmjavaMatch7.0.1.0
OR
ibmjavaMatch7.0.2.0
OR
ibmjavaMatch7.0.3.0
OR
ibmjavaMatch7.0.4.0
OR
ibmjavaMatch7.0.4.1
OR
ibmjavaMatch7.0.4.2
Node
ibmjavaMatch6.0.0.0
OR
ibmjavaMatch6.0.1.0
OR
ibmjavaMatch6.0.2.0
OR
ibmjavaMatch6.0.3.0
OR
ibmjavaMatch6.0.4.0
OR
ibmjavaMatch6.0.5.0
OR
ibmjavaMatch6.0.6.0
OR
ibmjavaMatch6.0.7.0
OR
ibmjavaMatch6.0.8.0
OR
ibmjavaMatch6.0.8.1
OR
ibmjavaMatch6.0.9.0
OR
ibmjavaMatch6.0.9.1
OR
ibmjavaMatch6.0.9.2
OR
ibmjavaMatch6.0.10.0
OR
ibmjavaMatch6.0.10.1
OR
ibmjavaMatch6.0.11.0
OR
ibmjavaMatch6.0.12.0
OR
ibmjavaMatch6.0.13.0
OR
ibmjavaMatch6.0.13.1
OR
ibmjavaMatch6.0.13.2
Node
ibmjavaMatch5.0.0.0
OR
ibmjavaMatch5.0.11.0
OR
ibmjavaMatch5.0.11.1
OR
ibmjavaMatch5.0.11.2
OR
ibmjavaMatch5.0.12.0
OR
ibmjavaMatch5.0.12.1
OR
ibmjavaMatch5.0.12.2
OR
ibmjavaMatch5.0.12.3
OR
ibmjavaMatch5.0.12.4
OR
ibmjavaMatch5.0.12.5
OR
ibmjavaMatch5.0.13.0
OR
ibmjavaMatch5.0.14.0
OR
ibmjavaMatch5.0.15.0
OR
ibmjavaMatch5.0.16.0
OR
ibmjavaMatch5.0.16.1
OR
ibmjavaMatch5.0.16.2
VendorProductVersionCPE
ibmjava1.4.2cpe:2.3:a:ibm:java:1.4.2:*:*:*:*:*:*:*
ibmjava1.4.2.13cpe:2.3:a:ibm:java:1.4.2.13:*:*:*:*:*:*:*
ibmjava1.4.2.13.1cpe:2.3:a:ibm:java:1.4.2.13.1:*:*:*:*:*:*:*
ibmjava1.4.2.13.2cpe:2.3:a:ibm:java:1.4.2.13.2:*:*:*:*:*:*:*
ibmjava1.4.2.13.3cpe:2.3:a:ibm:java:1.4.2.13.3:*:*:*:*:*:*:*
ibmjava1.4.2.13.4cpe:2.3:a:ibm:java:1.4.2.13.4:*:*:*:*:*:*:*
ibmjava1.4.2.13.5cpe:2.3:a:ibm:java:1.4.2.13.5:*:*:*:*:*:*:*
ibmjava1.4.2.13.6cpe:2.3:a:ibm:java:1.4.2.13.6:*:*:*:*:*:*:*
ibmjava1.4.2.13.7cpe:2.3:a:ibm:java:1.4.2.13.7:*:*:*:*:*:*:*
ibmjava1.4.2.13.8cpe:2.3:a:ibm:java:1.4.2.13.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 621

References

Social References

More

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0.032

Percentile

91.2%