PT-2013-1721 · Ibm+1 · Ibm Rational Host On-Demand+10

Adam Gowdiak

·

Published

2012-11-15

·

Updated

2019-07-18

·

CVE-2012-4823

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Java versions 7 SR2 and earlier IBM Java versions 6.0.1 SR3 and earlier IBM Java versions 6 SR11 and earlier IBM Java versions 5 SR14 and earlier IBM Java 142 SR13 FP13 and earlier
Description The issue allows remote attackers to execute arbitrary code via vectors related to insecure use of the java.lang.ClassLoader defineClass() method. This affects various IBM products, including IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager, as well as products from other vendors like Red Hat.
Recommendations For IBM Java versions 7 SR2 and earlier, update to a version later than 7 SR2. For IBM Java versions 6.0.1 SR3 and earlier, update to a version later than 6.0.1 SR3. For IBM Java versions 6 SR11 and earlier, update to a version later than 6 SR11. For IBM Java versions 5 SR14 and earlier, update to a version later than 5 SR14. For IBM Java 142 SR13 FP13 and earlier, update to a version later than 142 SR13 FP13. As a temporary workaround, consider restricting the use of the java.lang.ClassLoader defineClass() method until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2012-4823
RHSA-2012:1466
RHSA-2012:1467
RHSA-2012_1466
RHSA-2012_1467
RHSA-2013:1455
RHSA-2013:1456

Affected Products

Ibm Java
Ibm Rational Host On-Demand
Lotus Notes & Domino
Rational Change
Red Hat
Service Deliver Manager
Smart Analytics System 5600
Tivoli Monitoring
Ibm Tivoli Remote Control
Ibm Tivoli Storage Productivity Center
Ibm Websphere Real Time