8.1
CVSSv3

CVE-2016-0376

Published: 03/06/2016 Updated: 12/09/2023
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote malicious users to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.

Vulnerable Product Search on Vulmon Subscribe to Product

novell suse manager 2.1

novell suse linux enterprise server 11.0

novell suse manager proxy 2.1

novell suse linux enterprise server 12.0

novell suse linux enterprise module for legacy software 12

novell suse openstack cloud 5

novell suse linux enterprise software development kit 11.0

novell suse linux enterprise software development kit 12.0

ibm java sdk

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat satellite 5.7

redhat enterprise linux hpc node supplementary 6.0

redhat enterprise linux server 7.0

redhat enterprise linux workstation 5.0

redhat enterprise linux server eus 7.2

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux desktop 5.0

redhat enterprise linux hpc node supplementary 7.0

redhat enterprise linux server eus 7.3

redhat enterprise linux server eus 7.4

redhat enterprise linux server eus 7.5

redhat satellite 5.6

redhat enterprise linux server eus 6.7

Vendor Advisories

Synopsis Moderate: java-171-ibm security update Type/Severity Security Advisory: Moderate Topic An update for java-171-ibm is now available for Red HatSatellite 57 and Red Hat Satellite 56Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Sc ...
The comibmrmiioSunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (601625), 6 R1 before SR8 FP25 (61825), 7 before SR9 FP40 (70940), 7 R1 before SR3 FP40 (71340), and 8 before SR3 (8030) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers ...