2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2016-0363" ,
"sourceIdentifier" : "psirt@us.ibm.com" ,
"published" : "2016-06-03T14:59:01.530" ,
2024-11-23 05:11:48 +00:00
"lastModified" : "2024-11-21T02:41:33.660" ,
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009."
} ,
{
"lang" : "es" ,
"value" : "La clase com.ibm.CORBA.iiop.ClientDelegate en IBM SDK, Java Technology Edition 6 en versiones anteriores a SR16 FP25 (6.0.16.25), 6 R1 en versiones anteriores a SR8 FP25 (6.1.8.25), 7 en versiones anteriores a SR9 FP40 (7.0.9.40), 7 R1 en versiones anteriores a SR3 FP40 (7.1.3.40) y 8 en versiones anteriores a SR3 (8.0.3.0) utiliza el m\u00e9todo de invocaci\u00f3n de la clase java.lang.reflect.Method en un bloque AccessController doPrivileged, lo que permite a atacantes remotos llamar a setSecurityManager y eludir un mecanismo de protecci\u00f3n sandbox a trav\u00e9s de vectores relacionados con una instancia a un objeto Proxy implementando la interfaz java.lang.reflect.InvocationHandler. NOTA: esta vulnerabilidad existe debido a una soluci\u00f3n incompleta para CVE-2013-3009."
}
] ,
"metrics" : {
"cvssMetricV30" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.0" ,
"vectorString" : "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
2024-11-23 05:11:48 +00:00
"baseScore" : 8.1 ,
"baseSeverity" : "HIGH" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-11-23 05:11:48 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 2.2 ,
"impactScore" : 5.9
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P" ,
2024-11-23 05:11:48 +00:00
"baseScore" : 6.8 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
2024-11-23 05:11:48 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-20"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:redhat:satellite:5.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D4840254-CC76-4113-BC61-360BD15582B9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:redhat:satellite:5.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "85EA16E0-9261-45C4-840F-5366E9EAC5E1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EE249E1B-A1FD-4E08-AA71-A0E1F10FFE97"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "33C068A4-3780-4EAB-A937-6082DF847564"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_supplementary:6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "585614D3-1DAA-4256-83DE-AFE901154808"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:redhat:enterprise_linux_hpc_node_supplementary:7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8440BA16-EAC4-4F27-99A4-795295DA6646"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9BBCD86A-E6C7-4444-9D74-F861084090F0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "51EF4996-72F4-4FA4-814F-F5991E7A8318"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:6.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6C81647C-9A53-481D-A54C-36770A093F90"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "44B067C7-735E-43C9-9188-7E1522A02491"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A8442C20-41F9-47FD-9A12-E724D3A31FD7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9EC0D196-F7B8-4BDD-9050-779F7A7FBEE4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A4E9DD8A-A68B-4A69-8B01-BFF92A2020A8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E5ED5807-55B7-47C5-97A6-03233F4FBC3A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "825ECE2D-E232-46E0-A047-074B34DB1E97"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
2023-09-12 16:00:29 +00:00
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:11.0:sp4:*:*:*:*:*:*" ,
"matchCriteriaId" : "A5FDEDA8-6F51-4945-B443-438CC987F235"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "336EC5B8-6FD8-42BB-9530-58A15238CEE1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:12.0:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "01E6CAD9-DC1F-4C7C-8C8E-98E4BFABAC94"
} ,
2023-04-24 12:24:31 +02:00
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:novell:suse_linux_enterprise_module_for_legacy_software:12:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B7449208-3D08-427B-9783-CF48D6B63A6B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:sp2:*:*:ltss:*:*:*" ,
"matchCriteriaId" : "772B084E-2EAE-4AC9-94C1-B826857B0861"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:sp3:*:*:ltss:*:*:*" ,
"matchCriteriaId" : "3F8CE3BD-993B-407F-BAEC-A070F6B46E6E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:novell:suse_linux_enterprise_server:11.0:sp4:*:*:*:*:*:*" ,
"matchCriteriaId" : "ADE9D807-6690-4D67-A6B3-68BBC9B50153"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C384D0B6-8A5C-45CA-8CD9-7F4E967FE4F0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "81D94366-47D6-445A-A811-39327B150FCD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:novell:suse_manager:2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "514646C5-C5D4-487E-8950-B3A2B1DE8EEC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:novell:suse_manager_proxy:2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C15BA04F-6CBC-45AB-A44F-D8E8B3F8EC06"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:novell:suse_openstack_cloud:5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "74268F7D-058C-4E84-9D7E-3853A95918BD"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*" ,
"versionStartIncluding" : "6.0.0.0" ,
"versionEndExcluding" : "6.0.16.25" ,
"matchCriteriaId" : "A27846D2-F8BC-4A9B-9B59-E6E71BB869BC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*" ,
"versionStartIncluding" : "6.1.0.0" ,
"versionEndExcluding" : "6.1.8.25" ,
"matchCriteriaId" : "9F139472-2499-44AF-A466-0043BB83E254"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*" ,
"versionStartIncluding" : "7.0.0.0" ,
"versionEndExcluding" : "7.0.9.40" ,
"matchCriteriaId" : "A44B197F-40EF-465F-9995-691EA879F121"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*" ,
"versionStartIncluding" : "7.1.0.0" ,
"versionEndExcluding" : "7.1.3.40" ,
"matchCriteriaId" : "626BA0D0-5526-4344-822B-0F5837C43C37"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*" ,
"versionStartIncluding" : "8.0.0.0" ,
"versionEndExcluding" : "8.0.3.0" ,
"matchCriteriaId" : "DDBE9092-9478-4899-88D2-95E4EDACB4FD"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://rhn.redhat.com/errata/RHSA-2016-0701.html" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "http://rhn.redhat.com/errata/RHSA-2016-0702.html" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "http://rhn.redhat.com/errata/RHSA-2016-0708.html" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "http://rhn.redhat.com/errata/RHSA-2016-0716.html" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "http://rhn.redhat.com/errata/RHSA-2016-1039.html" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "http://seclists.org/fulldisclosure/2016/Apr/20" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://seclists.org/fulldisclosure/2016/Apr/3" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IX90172" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980826" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www.security-explorations.com/materials/SE-2012-01-IBM-4.pdf" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www.securityfocus.com/bid/85895" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www.securitytracker.com/id/1035953" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2016:1430" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2017:1216" ,
"source" : "psirt@us.ibm.com" ,
"tags" : [
"Third Party Advisory"
]
2024-11-23 05:11:48 +00:00
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory"
]
} ,
{
"url" : "http://rhn.redhat.com/errata/RHSA-2016-0701.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "http://rhn.redhat.com/errata/RHSA-2016-0702.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "http://rhn.redhat.com/errata/RHSA-2016-0708.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "http://rhn.redhat.com/errata/RHSA-2016-0716.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "http://rhn.redhat.com/errata/RHSA-2016-1039.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "http://seclists.org/fulldisclosure/2016/Apr/20" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://seclists.org/fulldisclosure/2016/Apr/3" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Mailing List" ,
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg1IX90172" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www-01.ibm.com/support/docview.wss?uid=swg21980826" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www.security-explorations.com/materials/SE-2012-01-IBM-4.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www.securityfocus.com/bid/85895" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "http://www.securitytracker.com/id/1035953" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2016:1430" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2017:1216" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}