8.1

CVE-2016-0376

The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NovellSuse Linux Enterprise Server Version11.0 Updatesp2 SwEditionltss
NovellSuse Linux Enterprise Server Version11.0 Updatesp3 SwEditionltss
NovellSuse Linux Enterprise Server Version11.0 Updatesp4
NovellSuse Linux Enterprise Server Version12.0 Updatesp1
NovellSuse Manager Version2.1
NovellSuse Manager Proxy Version2.1
IbmJava Sdk SwEditiontechnology Version >= 6.0.0.0 < 6.0.16.25
IbmJava Sdk SwEditiontechnology Version >= 6.1.0.0 < 6.1.8.25
IbmJava Sdk SwEditiontechnology Version >= 7.0.0.0 < 7.0.9.40
IbmJava Sdk SwEditiontechnology Version >= 7.1.0.0 < 7.1.3.40
IbmJava Sdk SwEditiontechnology Version >= 8.0.0.0 < 8.0.3.0
RedhatSatellite Version5.6
RedhatSatellite Version5.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.93% 0.826
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
http://www.securitytracker.com/id/1035953
Third Party Advisory
VDB Entry
http://seclists.org/fulldisclosure/2016/Apr/43
Third Party Advisory
VDB Entry
Mailing List
http://www.securityfocus.com/bid/89192
Third Party Advisory
VDB Entry