The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Java | Ibm | 7.0.0.0 (including) | 7.0.0.0 (including) |
Supplementary for Red Hat Enterprise Linux 5 | RedHat | java-1.7.0-ibm-1:1.7.0.6.0-1jpp.1.el5_10 | * |
Supplementary for Red Hat Enterprise Linux 6 | RedHat | java-1.7.0-ibm-1:1.7.0.6.0-1jpp.1.el6_4 | * |