Description
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.
Published: 2016-06-03
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2016-0398 The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.
References
History

No history.

Subscriptions

Ibm Java Sdk
Novell Suse Linux Enterprise Module For Legacy Software Suse Linux Enterprise Server Suse Linux Enterprise Software Development Kit Suse Manager Suse Manager Proxy Suse Openstack Cloud
Redhat Enterprise Linux Desktop Enterprise Linux Hpc Node Supplementary Enterprise Linux Server Enterprise Linux Server Eus Enterprise Linux Workstation Network Satellite Rhel Extras Satellite
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2024-08-05T22:15:24.000Z

Reserved: 2015-12-08T00:00:00.000Z

Link: CVE-2016-0363

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-06-03T14:59:01.530

Modified: 2025-04-12T10:46:40.837

Link: CVE-2016-0363

cve-icon Redhat

Severity : Critical

Publid Date: 2016-04-04T00:00:00Z

Links: CVE-2016-0363 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses