Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-5456

Опубликовано: 05 нояб. 2013
Источник: redhat
CVSS2: 6.8

Описание

The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5java-1.5.0-ibmNot affected
Red Hat Enterprise Linux 5java-1.6.0-ibmNot affected
Red Hat Enterprise Linux 6java-1.5.0-ibmNot affected
Red Hat Enterprise Linux 6java-1.6.0-ibmNot affected
Supplementary for Red Hat Enterprise Linux 5java-1.7.0-ibmFixedRHSA-2013:150707.11.2013
Supplementary for Red Hat Enterprise Linux 6java-1.7.0-ibmFixedRHSA-2013:150707.11.2013

Показывать по

Дополнительная информация

Статус:

Critical
https://bugzilla.redhat.com/show_bug.cgi?id=1027748JDK: unspecified sandbox bypass (ORB)

6.8 Medium

CVSS2

Связанные уязвимости

nvd
около 12 лет назад

The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.

github
больше 3 лет назад

The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.

suse-cvrf
около 11 лет назад

Security update for IBM Java

suse-cvrf
около 11 лет назад

Security update for IBM Java

suse-cvrf
около 11 лет назад

Security update for IBM Java

6.8 Medium

CVSS2