8.1
CVE-2016-0363
- EPSS 3.98%
- Veröffentlicht 03.06.2016 14:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Supplementary Version 6.0
Redhat ≫ Enterprise Linux Hpc Node Supplementary Version 7.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Eus Version 6.7
Redhat ≫ Enterprise Linux Server Eus Version 7.2
Redhat ≫ Enterprise Linux Server Eus Version 7.3
Redhat ≫ Enterprise Linux Server Eus Version 7.4
Redhat ≫ Enterprise Linux Server Eus Version 7.5
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
Novell ≫ Suse Linux Enterprise Software Development Kit Version 11.0 Update sp4
Novell ≫ Suse Linux Enterprise Software Development Kit Version 12.0
Novell ≫ Suse Linux Enterprise Software Development Kit Version 12.0 Update sp1
Novell ≫ Suse Linux Enterprise Module For Legacy Software Version 12
Novell ≫ Suse Linux Enterprise Server Version 11.0 Update sp2 SwEdition ltss
Novell ≫ Suse Linux Enterprise Server Version 11.0 Update sp3 SwEdition ltss
Novell ≫ Suse Linux Enterprise Server Version 11.0 Update sp4
Novell ≫ Suse Linux Enterprise Server Version 12.0
Novell ≫ Suse Linux Enterprise Server Version 12.0 Update sp1
Novell ≫ Suse Manager Version 2.1
Novell ≫ Suse Manager Proxy Version 2.1
Novell ≫ Suse Openstack Cloud Version 5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.98% | 0.892 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.1 | 2.2 | 5.9 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://seclists.org/fulldisclosure/2016/Apr/20
http://seclists.org/fulldisclosure/2016/Apr/3
http://www.security-explorations.com/materials/SE-2012-01-IBM-4.pdf
https://access.redhat.com/errata/RHSA-2016:1430
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html
http://rhn.redhat.com/errata/RHSA-2016-0701.html
http://rhn.redhat.com/errata/RHSA-2016-0702.html
http://rhn.redhat.com/errata/RHSA-2016-0708.html
http://rhn.redhat.com/errata/RHSA-2016-0716.html
http://rhn.redhat.com/errata/RHSA-2016-1039.html
https://access.redhat.com/errata/RHSA-2017:1216
http://www-01.ibm.com/support/docview.wss?uid=swg21980826
http://www.securitytracker.com/id/1035953
http://www-01.ibm.com/support/docview.wss?uid=swg1IX90172
http://www.securityfocus.com/bid/85895