CVE-2013-5458
published 2013-11-24CVE-2013-5458: Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.
PriorityP351critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.39%
91.7th percentile
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | java | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: unspecified sandbox bypass (XML)
vendor_redhat·2013-11-05·CVSS 9.3
CVE-2013-5458 [CRITICAL] JDK: unspecified sandbox bypass (XML)
JDK: unspecified sandbox bypass (XML)
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.6.0-ibm (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-936c-9m2v-j9p6: Unspecified vulnerability in IBM Java SDK 7
ghsa_unreviewed·2022-05-17
CVE-2013-5458 [HIGH] GHSA-936c-9m2v-j9p6: Unspecified vulnerability in IBM Java SDK 7
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5458 IBM JDK: unspecified sandbox bypass (XML)
bugzilla·2013-11-07·CVSS 9.3
CVE-2013-5458 [CRITICAL] CVE-2013-5458 IBM JDK: unspecified sandbox bypass (XML)
CVE-2013-5458 IBM JDK: unspecified sandbox bypass (XML)
An unspecified Java sandbox bypass issue in the XML component was fixed in IBM JDK 7 SR6. This issue got the following CVSSv2 score upstream: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
https://www.ibm.com/developerworks/java/jdk/aix/j732/Java7.fixes.html#SR6
Further info is available in this WebSphere Real Time security bulletin:
http://www-01.ibm.com/support/docview.wss?uid=swg21655202&myns=swgws&mynp=OCSSSTCZ&mync=R
CVE-2013-5456, CVE-2013-5457 and CVE-2013-5458 allow code running under a
security manager to escalate its privileges by modifying or removing the
security manager.
Additional details may become available under this X-Force database article:
Bugzilla
CVE-2013-5456 IBM JDK: unspecified sandbox bypass (ORB)
bugzilla·2013-11-07·CVSS 9.3
CVE-2013-5456 [CRITICAL] CVE-2013-5456 IBM JDK: unspecified sandbox bypass (ORB)
CVE-2013-5456 IBM JDK: unspecified sandbox bypass (ORB)
An unspecified Java sandbox bypass issue in the ORB component was fixed in IBM JDK 7 SR6. This issue got the following CVSSv2 score upstream: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
https://www.ibm.com/developerworks/java/jdk/aix/j732/Java7.fixes.html#SR6
Further info is available in this WebSphere Real Time security bulletin:
http://www-01.ibm.com/support/docview.wss?uid=swg21655202&myns=swgws&mynp=OCSSSTCZ&mync=R
CVE-2013-5456, CVE-2013-5457 and CVE-2013-5458 allow code running under a
security manager to escalate its privileges by modifying or removing the
security manager.
Additional details may become available under this X-Force database article:
Bugzilla
CVE-2013-5457 IBM JDK: unspecified sandbox bypass (ORB)
bugzilla·2013-11-07·CVSS 9.3
CVE-2013-5457 [CRITICAL] CVE-2013-5457 IBM JDK: unspecified sandbox bypass (ORB)
CVE-2013-5457 IBM JDK: unspecified sandbox bypass (ORB)
An unspecified Java sandbox bypass issue in the ORB component was fixed in IBM JDK 7 SR6 and 6 SR15. This issue got the following CVSSv2 score upstream: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
https://www.ibm.com/developerworks/java/jdk/aix/j732/Java7.fixes.html#SR6
https://www.ibm.com/developerworks/java/jdk/aix/j632/Java6.fixes.html#SR15
Further info is available in this WebSphere Real Time security bulletin:
http://www-01.ibm.com/support/docview.wss?uid=swg21655202&myns=swgws&mynp=OCSSSTCZ&mync=R
CVE-2013-5456, CVE-2013-5457 and CVE-2013-5458 allow code running under a
security manager to escalate its privileges by modifying or removing the
security m
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1507.htmlhttp://secunia.com/advisories/56338http://www-01.ibm.com/support/docview.wss?uid=swg1IV51328http://www-01.ibm.com/support/docview.wss?uid=swg21655201http://www-01.ibm.com/support/docview.wss?uid=swg21655202https://exchange.xforce.ibmcloud.com/vulnerabilities/88257https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1507.htmlhttp://secunia.com/advisories/56338http://www-01.ibm.com/support/docview.wss?uid=swg1IV51328http://www-01.ibm.com/support/docview.wss?uid=swg21655201http://www-01.ibm.com/support/docview.wss?uid=swg21655202https://exchange.xforce.ibmcloud.com/vulnerabilities/88257https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
2013-11-24
Published