PT-2013-4093 · Ibm+2 · Ibm Java+2

Adam Gowdiak

·

Published

2013-07-15

·

Updated

2017-11-29

·

CVE-2013-3009

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Java versions 1.4.2 before 1.4.2 SR13-FP18 IBM Java versions 5.0 before 5.0 SR16-FP3 IBM Java versions 6 before 6 SR14 IBM Java versions 6.0.1 before 6.0.1 SR6 IBM Java versions 7 before 7 SR5
Description The issue allows remote attackers to bypass a sandbox protection mechanism. This is achieved by exploiting the improper exposure of the invoke method of the java.lang.reflect.Method class in the com.ibm.CORBA.iiop.ClientDelegate class. The attack vectors are related to the AccessController doPrivileged block, enabling attackers to call setSecurityManager.
Recommendations For IBM Java version 1.4.2, update to 1.4.2 SR13-FP18 or later. For IBM Java version 5.0, update to 5.0 SR16-FP3 or later. For IBM Java version 6, update to 6 SR14 or later. For IBM Java version 6.0.1, update to 6.0.1 SR6 or later. For IBM Java version 7, update to 7 SR5 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2013-3009
RHSA-2013:1059
RHSA-2013:1060
RHSA-2013:1081
RHSA-2013_1059
RHSA-2013_1060
RHSA-2013_1081

Affected Products

Ibm Java
Red Hat
Suse