8.1

CVE-2016-0363

The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.

Data is provided by the National Vulnerability Database (NVD)
RedhatSatellite Version5.6
RedhatSatellite Version5.7
NovellSuse Linux Enterprise Server Version11.0 Updatesp2 SwEditionltss
NovellSuse Linux Enterprise Server Version11.0 Updatesp3 SwEditionltss
NovellSuse Linux Enterprise Server Version11.0 Updatesp4
NovellSuse Linux Enterprise Server Version12.0 Updatesp1
NovellSuse Manager Version2.1
NovellSuse Manager Proxy Version2.1
IbmJava Sdk SwEditiontechnology Version >= 6.0.0.0 < 6.0.16.25
IbmJava Sdk SwEditiontechnology Version >= 6.1.0.0 < 6.1.8.25
IbmJava Sdk SwEditiontechnology Version >= 7.0.0.0 < 7.0.9.40
IbmJava Sdk SwEditiontechnology Version >= 7.1.0.0 < 7.1.3.40
IbmJava Sdk SwEditiontechnology Version >= 8.0.0.0 < 8.0.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.64% 0.696
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://seclists.org/fulldisclosure/2016/Apr/20
Third Party Advisory
VDB Entry
Mailing List
http://seclists.org/fulldisclosure/2016/Apr/3
Third Party Advisory
VDB Entry
Mailing List
http://www.securitytracker.com/id/1035953
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/85895
Third Party Advisory
VDB Entry