CVE-2013-5457
published 2013-11-24CVE-2013-5457: Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to execute arbitrary code via…
PriorityP352critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.10%
92.6th percentile
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to execute arbitrary code via unspecified vectors.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p7vj-c6jh-2j22: Unspecified vulnerability in IBM Java SDK 7
ghsa_unreviewed·2022-05-17
CVE-2013-5457 [HIGH] GHSA-p7vj-c6jh-2j22: Unspecified vulnerability in IBM Java SDK 7
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to execute arbitrary code via unspecified vectors.
Red Hat
JDK: unspecified sandbox bypass (ORB)
vendor_redhat·2013-11-05·CVSS 9.3
CVE-2013-5457 [CRITICAL] JDK: unspecified sandbox bypass (ORB)
JDK: unspecified sandbox bypass (ORB)
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to execute arbitrary code via unspecified vectors.
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5458 IBM JDK: unspecified sandbox bypass (XML)
bugzilla·2013-11-07·CVSS 9.3
CVE-2013-5458 [CRITICAL] CVE-2013-5458 IBM JDK: unspecified sandbox bypass (XML)
CVE-2013-5458 IBM JDK: unspecified sandbox bypass (XML)
An unspecified Java sandbox bypass issue in the XML component was fixed in IBM JDK 7 SR6. This issue got the following CVSSv2 score upstream: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
https://www.ibm.com/developerworks/java/jdk/aix/j732/Java7.fixes.html#SR6
Further info is available in this WebSphere Real Time security bulletin:
http://www-01.ibm.com/support/docview.wss?uid=swg21655202&myns=swgws&mynp=OCSSSTCZ&mync=R
CVE-2013-5456, CVE-2013-5457 and CVE-2013-5458 allow code running under a
security manager to escalate its privileges by modifying or removing the
security manager.
Additional details may become available under this X-Force database article:
Bugzilla
CVE-2013-5456 IBM JDK: unspecified sandbox bypass (ORB)
bugzilla·2013-11-07·CVSS 9.3
CVE-2013-5456 [CRITICAL] CVE-2013-5456 IBM JDK: unspecified sandbox bypass (ORB)
CVE-2013-5456 IBM JDK: unspecified sandbox bypass (ORB)
An unspecified Java sandbox bypass issue in the ORB component was fixed in IBM JDK 7 SR6. This issue got the following CVSSv2 score upstream: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
https://www.ibm.com/developerworks/java/jdk/aix/j732/Java7.fixes.html#SR6
Further info is available in this WebSphere Real Time security bulletin:
http://www-01.ibm.com/support/docview.wss?uid=swg21655202&myns=swgws&mynp=OCSSSTCZ&mync=R
CVE-2013-5456, CVE-2013-5457 and CVE-2013-5458 allow code running under a
security manager to escalate its privileges by modifying or removing the
security manager.
Additional details may become available under this X-Force database article:
Bugzilla
CVE-2013-5457 IBM JDK: unspecified sandbox bypass (ORB)
bugzilla·2013-11-07·CVSS 9.3
CVE-2013-5457 [CRITICAL] CVE-2013-5457 IBM JDK: unspecified sandbox bypass (ORB)
CVE-2013-5457 IBM JDK: unspecified sandbox bypass (ORB)
An unspecified Java sandbox bypass issue in the ORB component was fixed in IBM JDK 7 SR6 and 6 SR15. This issue got the following CVSSv2 score upstream: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
https://www.ibm.com/developerworks/java/jdk/aix/j732/Java7.fixes.html#SR6
https://www.ibm.com/developerworks/java/jdk/aix/j632/Java6.fixes.html#SR15
Further info is available in this WebSphere Real Time security bulletin:
http://www-01.ibm.com/support/docview.wss?uid=swg21655202&myns=swgws&mynp=OCSSSTCZ&mync=R
CVE-2013-5456, CVE-2013-5457 and CVE-2013-5458 allow code running under a
security manager to escalate its privileges by modifying or removing the
security m
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1507.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1508.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1793.htmlhttp://secunia.com/advisories/56338http://www-01.ibm.com/support/docview.wss?uid=swg1IV51334http://www-01.ibm.com/support/docview.wss?uid=swg21655201http://www-01.ibm.com/support/docview.wss?uid=swg21655202https://exchange.xforce.ibmcloud.com/vulnerabilities/88256https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1507.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1508.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1793.htmlhttp://secunia.com/advisories/56338http://www-01.ibm.com/support/docview.wss?uid=swg1IV51334http://www-01.ibm.com/support/docview.wss?uid=swg21655201http://www-01.ibm.com/support/docview.wss?uid=swg21655202https://exchange.xforce.ibmcloud.com/vulnerabilities/88256https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
2013-11-24
Published