CVE Vulnerabilities

CVE-2013-5456

Published: Nov 24, 2013 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu

The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.

Affected Software

Name Vendor Start Version End Version
Java Ibm 7.0.0.0 (including) 7.0.0.0 (including)
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.7.0-ibm-1:1.7.0.6.0-1jpp.1.el5_10 *
Supplementary for Red Hat Enterprise Linux 6 RedHat java-1.7.0-ibm-1:1.7.0.6.0-1jpp.1.el6_4 *

References