cbcvebase.
CVE-2013-5456
published 2013-11-24

CVE-2013-5456: The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute…

critical9.3CVSS 3.1
AVNACMAuNCCICAC
The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
ibmjava
ibmjava_sdk>= 6.0.0.0 < 6.0.16.256.0.16.25
ibmjava_sdk>= 6.1.0.0 < 6.1.8.256.1.8.25
ibmjava_sdk>= 7.0.0.0 < 7.0.9.407.0.9.40
ibmjava_sdk>= 7.1.0.0 < 7.1.3.407.1.3.40
ibmjava_sdk>= 8.0.0.0 < 8.0.3.08.0.3.0
novellsuse_linux_enterprise_module_for_legacy_software
novellsuse_linux_enterprise_server
novellsuse_linux_enterprise_server
novellsuse_linux_enterprise_software_development_kit
novellsuse_linux_enterprise_software_development_kit
novellsuse_manager
novellsuse_manager_proxy
novellsuse_openstack_cloud
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_hpc_node_supplementary
redhatenterprise_linux_hpc_node_supplementary
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus

CVSS provenance

nvd9.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H