CVE-2013-5456
24.11.2013, 18:55
The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | java | 7.0.0.0 |
𝑥
= Vulnerable software versions
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| java-1.7.0-ibm |
| ||
| java-1.7.0-ibm-demo |
| ||
| java-1.7.0-ibm-devel |
| ||
| java-1.7.0-ibm-jdbc |
| ||
| java-1.7.0-ibm-plugin |
| ||
| java-1.7.0-ibm-src |
|
References