vulnerability
SUSE: CVE-2016-0363: SUSE Linux Security Advisory
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:N/AC:M/Au:N/C:P/I:P/A:P) | May 13, 2016 | May 13, 2016 | Feb 8, 2021 |
Description
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.
Solution(s)
References
- SUSE-SUSE-SU-2016:1299
- SUSE-SUSE-SU-2016:1299-1
- SUSE-SUSE-SU-2016:1300
- SUSE-SUSE-SU-2016:1300-1
- SUSE-SUSE-SU-2016:1303
- SUSE-SUSE-SU-2016:1303-1
- SUSE-SUSE-SU-2016:1378
- SUSE-SUSE-SU-2016:1378-1
- SUSE-SUSE-SU-2016:1379
- SUSE-SUSE-SU-2016:1379-1
- SUSE-SUSE-SU-2016:1388
- SUSE-SUSE-SU-2016:1388-1
- SUSE-SUSE-SU-2016:1458
- SUSE-SUSE-SU-2016:1458-1
- SUSE-SUSE-SU-2016:1475
- SUSE-SUSE-SU-2016:1475-1
- REDHAT-RHSA-2016:0701
- REDHAT-RHSA-2016:0702
- REDHAT-RHSA-2016:0708
- REDHAT-RHSA-2016:0716
- REDHAT-RHSA-2016:1039
- REDHAT-RHSA-2016:1430
- REDHAT-RHSA-2017:1216
- BID-85895
- SECTRACK-1035953
- NVD-CVE-2016-0363

Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.