The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.

Project Subscriptions

Vendors Products
Java Sdk Subscribe
Suse Linux Enterprise Module For Legacy Software Subscribe
Suse Linux Enterprise Server Subscribe
Suse Linux Enterprise Software Development Kit Subscribe
Suse Manager Subscribe
Suse Manager Proxy Subscribe
Suse Openstack Cloud Subscribe
Enterprise Linux Desktop Subscribe
Enterprise Linux Hpc Node Supplementary Subscribe
Enterprise Linux Server Subscribe
Enterprise Linux Server Eus Subscribe
Enterprise Linux Workstation Subscribe
Network Satellite Subscribe
Rhel Extras Subscribe
Satellite Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2016-0398 The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-08-05T22:15:24.000Z

Reserved: 2015-12-08T00:00:00

Link: CVE-2016-0363

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-06-03T14:59:01.530

Modified: 2025-04-12T10:46:40.837

Link: CVE-2016-0363

cve-icon Redhat

Severity : Critical

Publid Date: 2016-04-04T00:00:00Z

Links: CVE-2016-0363 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses