CVE-2013-3009
published 2013-07-23CVE-2013-3009: The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7…
PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.38%
90.2th percentile
The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 improperly exposes the invoke method of the java.lang.reflect.Method class, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to the AccessController doPrivileged block.
Affected
90 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: insecure use of invoke method in CORBA component, incorrect CVE-2013-3009 fix
vendor_redhat·2016-04-04·CVSS 9.3
CVE-2016-0363 [CRITICAL] JDK: insecure use of invoke method in CORBA component, incorrect CVE-2013-3009 fix
JDK: insecure use of invoke method in CORBA component, incorrect CVE-2013-3009 fix
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.
Red Hat
JDK: Unspecified security fixes (July 2013)
vendor_redhat·2013-07-12·CVSS 9.3
CVE-2013-3009 [CRITICAL] JDK: Unspecified security fixes (July 2013)
JDK: Unspecified security fixes (July 2013)
The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 improperly exposes the invoke method of the java.lang.reflect.Method class, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to the AccessController doPrivileged block.
Red Hat
JDK: Unspecified security fixes (July 2013)
vendor_redhat·2013-07-12·CVSS 9.3
CVE-2013-3012 [CRITICAL] JDK: Unspecified security fixes (July 2013)
JDK: Unspecified security fixes (July 2013)
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3009 and CVE-2013-3011.
Red Hat
JDK: Unspecified security fixes (July 2013)
vendor_redhat·2013-07-12·CVSS 9.3
CVE-2013-3011 [CRITICAL] JDK: Unspecified security fixes (July 2013)
JDK: Unspecified security fixes (July 2013)
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3009 and CVE-2013-3012.
GHSA
GHSA-rpwx-9mqf-6hwr: Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2013-3011 [CRITICAL] GHSA-rpwx-9mqf-6hwr: Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3009 and CVE-2013-3012.
GHSA
GHSA-5wc9-xxxc-29xm: The com
ghsa_unreviewed·2022-05-17
CVE-2013-3009 [HIGH] GHSA-5wc9-xxxc-29xm: The com
The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 improperly exposes the invoke method of the java.lang.reflect.Method class, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to the AccessController doPrivileged block.
GHSA
GHSA-5924-8mpv-c4g3: Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2013-3012 [CRITICAL] GHSA-5924-8mpv-c4g3: Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3009 and CVE-2013-3011.
GHSA
GHSA-p824-48mj-5qcc: The com
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2016-0363 [CRITICAL] CWE-20 GHSA-p824-48mj-5qcc: The com
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0363 IBM JDK: insecure use of invoke method in CORBA component, incorrect CVE-2013-3009 fix
bugzilla·2016-04-05·CVSS 9.3
CVE-2016-0363 [CRITICAL] CVE-2016-0363 IBM JDK: insecure use of invoke method in CORBA component, incorrect CVE-2013-3009 fix
CVE-2016-0363 IBM JDK: insecure use of invoke method in CORBA component, incorrect CVE-2013-3009 fix
It was reported that the IBM fix for the issue 67 from this document http://www.security-explorations.com/materials/SE-2012-01-IBM-2.pdf didn't address the problem properly.
References:
http://seclists.org/fulldisclosure/2016/Apr/3
Full report:
http://www.security-explorations.com/materials/SE-2012-01-IBM-4.pdf
Discussion:
Issue 67 was previously tracked via bug 985501. However, as noted in bug 985501 comment 2, there is no public information allowing to map between Security Explorations' issue numbers and CVE ids mentioned in the bug report.
---
(In reply to Tomas Hoger from comment #1)
> Issue 67 was previously tracked via bug 985501. However, as noted in bug
> 985501 comment 2,
Bugzilla
CVE-2013-3006 CVE-2013-3007 CVE-2013-3008 CVE-2013-3009 CVE-2013-3010 CVE-2013-3011 CVE-2013-3012 IBM JDK: Unspecified security fixes (July 2013)
bugzilla·2013-07-17·CVSS 9.3
CVE-2013-3006 [CRITICAL] CVE-2013-3006 CVE-2013-3007 CVE-2013-3008 CVE-2013-3009 CVE-2013-3010 CVE-2013-3011 CVE-2013-3012 IBM JDK: Unspecified security fixes (July 2013)
CVE-2013-3006 CVE-2013-3007 CVE-2013-3008 CVE-2013-3009 CVE-2013-3010 CVE-2013-3011 CVE-2013-3012 IBM JDK: Unspecified security fixes (July 2013)
The July 2013 updates for the IBM JDK (5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5) contain patches for unspecified security flaws.
For the majority of the flaws, upstream has provided a CVSSv2 base score of 9.3, which suggests a CVSSv2 vector of AV:N/AC:M/Au:N/C:P/I:P/A:P. The exception is CVE-2013-4002 with a CVSSv2 base score of 7.1.
CVE CVSSv2 Score Fixed in
CVE-2013-3006 9.3 7 SR5
CVE-2013-3007 9.3 6.0.1 SR6, 7 SR5
CVE-2013-3008 9.3 7 SR5
CVE-2013-3009 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5
CVE-2013-3010 9.3 6.0.1 SR6, 7 SR5
CVE-2013-3011 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5
CVE-2013-3012 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5
CV
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1059.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1060.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1081.htmlhttp://seclists.org/fulldisclosure/2016/Apr/20http://seclists.org/fulldisclosure/2016/Apr/3http://secunia.com/advisories/54154http://www-01.ibm.com/support/docview.wss?uid=swg1IV44792http://www-01.ibm.com/support/docview.wss?uid=swg1IX90118http://www-01.ibm.com/support/docview.wss?uid=swg1PM91727http://www-01.ibm.com/support/docview.wss?uid=swg21642336http://www-01.ibm.com/support/docview.wss?uid=swg21644197http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_July_2013http://www.security-explorations.com/materials/SE-2012-01-IBM-2.pdfhttp://www.security-explorations.com/materials/SE-2012-01-IBM-4.pdfhttps://exchange.xforce.ibmcloud.com/vulnerabilities/84150http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1059.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1060.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1081.htmlhttp://seclists.org/fulldisclosure/2016/Apr/20http://seclists.org/fulldisclosure/2016/Apr/3http://secunia.com/advisories/54154http://www-01.ibm.com/support/docview.wss?uid=swg1IV44792http://www-01.ibm.com/support/docview.wss?uid=swg1IX90118http://www-01.ibm.com/support/docview.wss?uid=swg1PM91727http://www-01.ibm.com/support/docview.wss?uid=swg21642336http://www-01.ibm.com/support/docview.wss?uid=swg21644197http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_July_2013http://www.security-explorations.com/materials/SE-2012-01-IBM-2.pdfhttp://www.security-explorations.com/materials/SE-2012-01-IBM-4.pdfhttps://exchange.xforce.ibmcloud.com/vulnerabilities/84150
2013-07-23
Published