Lucene search

K
nvd[email protected]NVD:CVE-2013-3009
HistoryJul 23, 2013 - 11:03 a.m.

CVE-2013-3009

2013-07-2311:03:19
web.nvd.nist.gov

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

5.8 Medium

AI Score

Confidence

High

0.032 Low

EPSS

Percentile

91.2%

The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 improperly exposes the invoke method of the java.lang.reflect.Method class, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to the AccessController doPrivileged block.

Affected configurations

NVD
Node
ibmjavaMatch1.4.2
OR
ibmjavaMatch1.4.2.13
OR
ibmjavaMatch1.4.2.13.1
OR
ibmjavaMatch1.4.2.13.2
OR
ibmjavaMatch1.4.2.13.3
OR
ibmjavaMatch1.4.2.13.4
OR
ibmjavaMatch1.4.2.13.5
OR
ibmjavaMatch1.4.2.13.6
OR
ibmjavaMatch1.4.2.13.7
OR
ibmjavaMatch1.4.2.13.8
OR
ibmjavaMatch1.4.2.13.9
OR
ibmjavaMatch1.4.2.13.10
OR
ibmjavaMatch1.4.2.13.11
OR
ibmjavaMatch1.4.2.13.12
OR
ibmjavaMatch1.4.2.13.13
OR
ibmjavaMatch1.4.2.13.14
OR
ibmjavaMatch1.4.2.13.15
OR
ibmjavaMatch1.4.2.13.16
OR
ibmjavaMatch1.4.2.13.17
Node
ibmjavaMatch7.0.0.0
OR
ibmjavaMatch7.0.1.0
OR
ibmjavaMatch7.0.2.0
OR
ibmjavaMatch7.0.3.0
OR
ibmjavaMatch7.0.4.0
OR
ibmjavaMatch7.0.4.1
OR
ibmjavaMatch7.0.4.2
Node
ibmjavaMatch6.0.0.0
OR
ibmjavaMatch6.0.1.0
OR
ibmjavaMatch6.0.2.0
OR
ibmjavaMatch6.0.3.0
OR
ibmjavaMatch6.0.4.0
OR
ibmjavaMatch6.0.5.0
OR
ibmjavaMatch6.0.6.0
OR
ibmjavaMatch6.0.7.0
OR
ibmjavaMatch6.0.8.0
OR
ibmjavaMatch6.0.8.1
OR
ibmjavaMatch6.0.9.0
OR
ibmjavaMatch6.0.9.1
OR
ibmjavaMatch6.0.9.2
OR
ibmjavaMatch6.0.10.0
OR
ibmjavaMatch6.0.10.1
OR
ibmjavaMatch6.0.11.0
OR
ibmjavaMatch6.0.12.0
OR
ibmjavaMatch6.0.13.0
OR
ibmjavaMatch6.0.13.1
OR
ibmjavaMatch6.0.13.2
Node
ibmjavaMatch5.0.0.0
OR
ibmjavaMatch5.0.11.0
OR
ibmjavaMatch5.0.11.1
OR
ibmjavaMatch5.0.11.2
OR
ibmjavaMatch5.0.12.0
OR
ibmjavaMatch5.0.12.1
OR
ibmjavaMatch5.0.12.2
OR
ibmjavaMatch5.0.12.3
OR
ibmjavaMatch5.0.12.4
OR
ibmjavaMatch5.0.12.5
OR
ibmjavaMatch5.0.13.0
OR
ibmjavaMatch5.0.14.0
OR
ibmjavaMatch5.0.15.0
OR
ibmjavaMatch5.0.16.0
OR
ibmjavaMatch5.0.16.1
OR
ibmjavaMatch5.0.16.2

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

5.8 Medium

AI Score

Confidence

High

0.032 Low

EPSS

Percentile

91.2%