Description
The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-0411 | The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456. |
References
History
No history.
Subscriptions
Ibm
Subscribe
Java Sdk
Subscribe
Novell
Subscribe
Suse Linux Enterprise Module For Legacy Software
Subscribe
Suse Linux Enterprise Server
Subscribe
Suse Linux Enterprise Software Development Kit
Subscribe
Suse Manager
Subscribe
Suse Manager Proxy
Subscribe
Suse Openstack Cloud
Subscribe
Redhat
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Hpc Node Supplementary
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Eus
Subscribe
Enterprise Linux Workstation
Subscribe
Network Satellite
Subscribe
Rhel Extras
Subscribe
Satellite
Subscribe
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-05T22:15:24.181Z
Reserved: 2015-12-08T00:00:00.000Z
Link: CVE-2016-0376
No data.
Status : Deferred
Published: 2016-06-03T14:59:02.890
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-0376
OpenCVE Enrichment
No data.
Weaknesses
EUVD