Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-5456
HistoryNov 24, 2013 - 6:55 p.m.

Deserialization of untrusted data

2013-11-2418:55:00
PRIOn knowledge base
www.prio-n.com
8

7.8 High

AI Score

Confidence

Low

0.043 Low

EPSS

Percentile

92.3%

The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.

CPENameOperatorVersion
javaeq7.0.0.0

7.8 High

AI Score

Confidence

Low

0.043 Low

EPSS

Percentile

92.3%