9.3
CVSSv2

CVE-2013-5456

Published: 24/11/2013 Updated: 29/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote malicious users to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm java 7.0.0.0

Vendor Advisories

Synopsis Critical: java-170-ibm security update Type/Severity Security Advisory: Critical Topic Updated java-170-ibm packages that fix several security issues are nowavailable for Red Hat Enterprise Linux 5 and 6 SupplementaryThe Red Hat Security Response Team has rated this update as having criticalse ...
Synopsis Moderate: java-171-ibm security update Type/Severity Security Advisory: Moderate Topic An update for java-171-ibm is now available for Red HatSatellite 57 and Red Hat Satellite 56Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Sc ...

Recent Articles

Security researcher to IBM: 'Fix that 2013 Java bug'
The Register • Richard Chirgwin • 13 Apr 2016

And this time, do it right

A security researcher that pointed out serious Java Runtime Engine vulnerabilities to IBM in 2013 has accused Big Blue of not fixing the bugs properly. The gist of this Full Disclosure post is that back in 2013, IBM closed off the proof-of-concept attack without considering all possible code paths to the vulnerability. The message comes from Adam Gowdiak, who is credited with finding the flaw by IBM in this Security Bulletin. Gowdiak's new work explains that CVE-2013-5456 enabled a Java sandbox ...