PT-2013-1721 · Ibm+1 · Ibm Rational Host On-Demand+10
Adam Gowdiak
·
Published
2012-11-15
·
Updated
2019-07-18
·
CVE-2012-4823
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM Java versions 7 SR2 and earlier
IBM Java versions 6.0.1 SR3 and earlier
IBM Java versions 6 SR11 and earlier
IBM Java versions 5 SR14 and earlier
IBM Java 142 SR13 FP13 and earlier
Description
The issue allows remote attackers to execute arbitrary code via vectors related to insecure use of the
java.lang.ClassLoader defineClass() method. This affects various IBM products, including IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager, as well as products from other vendors like Red Hat.Recommendations
For IBM Java versions 7 SR2 and earlier, update to a version later than 7 SR2.
For IBM Java versions 6.0.1 SR3 and earlier, update to a version later than 6.0.1 SR3.
For IBM Java versions 6 SR11 and earlier, update to a version later than 6 SR11.
For IBM Java versions 5 SR14 and earlier, update to a version later than 5 SR14.
For IBM Java 142 SR13 FP13 and earlier, update to a version later than 142 SR13 FP13.
As a temporary workaround, consider restricting the use of the
java.lang.ClassLoader defineClass() method until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Java
Ibm Rational Host On-Demand
Lotus Notes & Domino
Rational Change
Red Hat
Service Deliver Manager
Smart Analytics System 5600
Tivoli Monitoring
Ibm Tivoli Remote Control
Ibm Tivoli Storage Productivity Center
Ibm Websphere Real Time