6.8
CVSSv2

CVE-2016-0363

Published: 03/06/2016 Updated: 12/09/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote malicious users to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat satellite 5.7

redhat enterprise linux hpc node supplementary 6.0

redhat enterprise linux server 7.0

redhat enterprise linux server eus 7.2

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux hpc node supplementary 7.0

redhat enterprise linux server eus 7.3

redhat enterprise linux server eus 7.4

redhat enterprise linux server eus 7.5

redhat satellite 5.6

redhat enterprise linux server eus 6.7

novell suse manager 2.1

novell suse linux enterprise server 11.0

novell suse manager proxy 2.1

novell suse linux enterprise server 12.0

novell suse linux enterprise module for legacy software 12

novell suse openstack cloud 5

novell suse linux enterprise software development kit 11.0

novell suse linux enterprise software development kit 12.0

ibm java sdk

Vendor Advisories

Synopsis Moderate: java-171-ibm security update Type/Severity Security Advisory: Moderate Topic An update for java-171-ibm is now available for Red HatSatellite 57 and Red Hat Satellite 56Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Sc ...
The comibmCORBAiiopClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (601625), 6 R1 before SR8 FP25 (61825), 7 before SR9 FP40 (70940), 7 R1 before SR3 FP40 (71340), and 8 before SR3 (8030) uses the invoke method of the javalangreflectMethod class in an AccessController doPrivileged block, which allow ...