CVE-2013-4041
published 2013-11-24CVE-2013-4041: Unspecified vulnerability in IBM Java SDK 5.0.0 before SR16 FP4, 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to access…
PriorityP434medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.81%
85.0th percentile
Unspecified vulnerability in IBM Java SDK 5.0.0 before SR16 FP4, 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to access restricted classes via unspecified vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x62c-8f45-jx5r: Unspecified vulnerability in IBM Java SDK 5
ghsa_unreviewed·2022-05-17
CVE-2013-4041 [MEDIUM] GHSA-x62c-8f45-jx5r: Unspecified vulnerability in IBM Java SDK 5
Unspecified vulnerability in IBM Java SDK 5.0.0 before SR16 FP4, 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to access restricted classes via unspecified vectors.
Red Hat
JDK: unspecified sandbox bypass (JVM)
vendor_redhat·2013-11-05·CVSS 6.8
CVE-2013-4041 [MEDIUM] JDK: unspecified sandbox bypass (JVM)
JDK: unspecified sandbox bypass (JVM)
Unspecified vulnerability in IBM Java SDK 5.0.0 before SR16 FP4, 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to access restricted classes via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5375 IBM JDK: unspecified sandbox bypass (XML)
bugzilla·2013-11-07·CVSS 6.8
CVE-2013-5375 [MEDIUM] CVE-2013-5375 IBM JDK: unspecified sandbox bypass (XML)
CVE-2013-5375 IBM JDK: unspecified sandbox bypass (XML)
An unspecified Java sandbox bypass issue in the XML component was fixed in IBM JDK 7 SR6, 6 SR15 and 5.0 SR16-FP4. This issue got the following CVSSv2 score upstream: 4.3/AV:N/AC:M/Au:N/C:N/I:P/A:N
https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
https://www.ibm.com/developerworks/java/jdk/aix/j732/Java7.fixes.html#SR6
https://www.ibm.com/developerworks/java/jdk/aix/j632/Java6.fixes.html#SR15
https://www.ibm.com/developerworks/java/jdk/aix/j532/fixes.html#SR16FP4
Further info is available in this WebSphere Real Time security bulletin:
http://www-01.ibm.com/support/docview.wss?uid=swg21655202&myns=swgws&mynp=OCSSSTCZ&mync=R
CVE-2013-4041 and CVE-2013-5375 allow code running under a security man
Bugzilla
CVE-2013-4041 IBM JDK: unspecified sandbox bypass (JVM)
bugzilla·2013-11-07·CVSS 6.8
CVE-2013-4041 [MEDIUM] CVE-2013-4041 IBM JDK: unspecified sandbox bypass (JVM)
CVE-2013-4041 IBM JDK: unspecified sandbox bypass (JVM)
An unspecified Java sandbox bypass issue in the JVM component was fixed in IBM JDK 7 SR6, 6 SR15 and 5.0 SR16-FP4. This issue got the following CVSSv2 score upstream: 6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P
https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
https://www.ibm.com/developerworks/java/jdk/aix/j732/Java7.fixes.html#SR6
https://www.ibm.com/developerworks/java/jdk/aix/j632/Java6.fixes.html#SR15
https://www.ibm.com/developerworks/java/jdk/aix/j532/fixes.html#SR16FP4
Further info is available in this WebSphere Real Time security bulletin:
http://www-01.ibm.com/support/docview.wss?uid=swg21655202&myns=swgws&mynp=OCSSSTCZ&mync=R
CVE-2013-4041 and CVE-2013-5375 allow code running under a security man
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1507.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1508.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1509.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1793.htmlhttp://secunia.com/advisories/56338http://www-01.ibm.com/support/docview.wss?uid=swg1IV51087http://www-01.ibm.com/support/docview.wss?uid=swg1IV51088http://www-01.ibm.com/support/docview.wss?uid=swg21655201http://www-01.ibm.com/support/docview.wss?uid=swg21655202https://exchange.xforce.ibmcloud.com/vulnerabilities/86416https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1507.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1508.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1509.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1793.htmlhttp://secunia.com/advisories/56338http://www-01.ibm.com/support/docview.wss?uid=swg1IV51087http://www-01.ibm.com/support/docview.wss?uid=swg1IV51088http://www-01.ibm.com/support/docview.wss?uid=swg21655201http://www-01.ibm.com/support/docview.wss?uid=swg21655202https://exchange.xforce.ibmcloud.com/vulnerabilities/86416https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
2013-11-24
Published