Ibm Java vulnerabilities
28 known vulnerabilities affecting ibm/java.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH4MEDIUM7LOW1
Vulnerabilities
Page 1 of 2
CVE-2012-4821P3CRITICALCVSS 9.3≥ 1.4.2, ≤ 1.4.2.13.13≥ 5.0.0.0, ≤ 5.0.14.0+2 more2013-01-11
CVE-2012-4821 [CRITICAL] CVE-2012-4821: Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lo
nvd
CVE-2012-4822P3CRITICALCVSS 9.3≥ 1.4.2, ≤ 1.4.2.13.13≥ 5.0.0.0, ≤ 5.0.14.0+2 more2013-01-11
CVE-2012-4822 [CRITICAL] CVE-2012-4822: Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lo
nvd
CVE-2012-4823P3CRITICALCVSS 9.3≥ 1.4.2, ≤ 1.4.2.13.13≥ 5.0.0.0, ≤ 5.0.14.0+2 more2013-01-11
CVE-2012-4823 [CRITICAL] CVE-2012-4823: Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and ear
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes
nvd
CVE-2013-5457P3CRITICALCVSS 9.3v6.0.0.0v6.0.1.0+1 more2013-11-24
CVE-2013-5457 [CRITICAL] CVE-2013-5457: Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2013-5456P3CRITICALCVSS 9.3v7.0.0.02013-11-24
CVE-2013-5456 [CRITICAL] CVE-2013-5456: The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attac
The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.
nvd
CVE-2013-5458P3CRITICALCVSS 9.3v7.0.0.02013-11-24
CVE-2013-5458 [CRITICAL] CVE-2013-5458: Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitr
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-4820P3CRITICALCVSS 9.3≥ 1.4.2, ≤ 1.4.2.13.13≥ 5.0.0.0, ≤ 5.0.14.0+2 more2013-01-11
CVE-2012-4820 [CRITICAL] CVE-2012-4820: Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and ear
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes
nvd
CVE-2015-0192P3CRITICALCVSS 9.8≥ 5.0.0.0, < 5.0.16.10≥ 6.0.0.0, ≤ 6.0.16.4+4 more2015-07-02
CVE-2015-0192 [CRITICAL] CWE-269 CVE-2015-0192: Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before
Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.
nvd
CVE-2013-3011P3CRITICALCVSS 9.3v5.0.0.0v5.0.11.0+60 more2013-07-23
CVE-2013-3011 [CRITICAL] CVE-2013-3011: Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3009 and CVE-2013-3012.
nvd
CVE-2013-3012P3CRITICALCVSS 9.3v5.0.0.0v5.0.11.0+60 more2013-07-23
CVE-2013-3012 [CRITICAL] CVE-2013-3012: Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3009 and CVE-2013-3011.
nvd
CVE-2013-4002P3HIGHCVSS 7.1v5.0.0.0v5.0.11.0+41 more2013-07-23
CVE-2013-4002 [HIGH] CVE-2013-4002: XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Jav
nvd
CVE-2013-3009P3CRITICALCVSS 9.3v1.4.2v1.4.2.13+60 more2013-07-23
CVE-2013-3009 [CRITICAL] CVE-2013-3009: The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0
The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 improperly exposes the invoke method of the java.lang.reflect.Method class, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors r
nvd
CVE-2013-3008P3CRITICALCVSS 9.3v7.0.0.0v7.0.1.0+5 more2013-07-23
CVE-2013-3008 [CRITICAL] CVE-2013-3008: Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows re
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3006.
nvd
CVE-2013-3010P3CRITICALCVSS 9.3v6.0.1.0v7.0.0.0+6 more2013-07-23
CVE-2013-3010 [CRITICAL] CVE-2013-3010: Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 a
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3007.
nvd
CVE-2013-3006P3CRITICALCVSS 9.3v7.0.0.0v7.0.1.0+5 more2013-07-23
CVE-2013-3006 [CRITICAL] CVE-2013-3006: Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows re
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3008.
nvd
CVE-2013-3007P3CRITICALCVSS 9.3v6.0.1.0v7.0.0.0+6 more2013-07-23
CVE-2013-3007 [CRITICAL] CVE-2013-3007: Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 a
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3006.
nvd
CVE-2023-30441P3HIGHCVSS 7.5≥ 8.0.7.0, < 8.0.7.15≥ 8.0.7.0, ≤ 8.0.7.112023-04-29
CVE-2023-30441 [HIGH] CWE-327 CVE-2023-30441: IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 compon
IBM Runtime Environment, Java Technology Edition IBMJCEPlus and JSSE 8.0.7.0 through 8.0.7.11 components could expose sensitive information using a combination of flaws and configurations. IBM X-Force ID: 253188.
nvd
CVE-2019-4473P3HIGHCVSS 7.8v7.0.0.0v7.1.4.50+4 more2019-08-05
CVE-2019-4473 [HIGH] CWE-427 CVE-2019-4473: Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure
Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984.
nvd
CVE-2013-5375P3MEDIUMCVSS 6.8v5.0.0.0v6.0.0.0+2 more2013-11-24
CVE-2013-5375 [MEDIUM] CVE-2013-5375: Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, 6.0.0 before SR15, and
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, 6.0.0 before SR15, and 5.0.0 before SR16 FP4 allows remote attackers to access restricted classes via unspecified vectors related to XML and XSL.
nvd
CVE-2015-1916P4HIGHCVSS 7.5v8.02015-07-02
CVE-2015-1916 [HIGH] CWE-400 CVE-2015-1916: Unspecified vulnerability in IBM Java 8 before SR1 allows remote attackers to cause a denial of serv
Unspecified vulnerability in IBM Java 8 before SR1 allows remote attackers to cause a denial of service via unknown vectors related to SSL/TLS and the Secure Socket Extension provider.
nvd
1 / 2Next →