CVE-2013-3009

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/07/2013
Last modified:
11/04/2025

Description

The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 improperly exposes the invoke method of the java.lang.reflect.Method class, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to the AccessController doPrivileged block.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:java:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13.12:*:*:*:*:*:*:*
cpe:2.3:a:ibm:java:1.4.2.13.13:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools