CVE-2013-3006: Critical severity IBM Java vulnerability
The July 2013 updates for the IBM JDK (5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5) contain patches for unspecified security flaws.
For the majority of the flaws, upstream has provided a CVSSv2 base score of 9.3, which suggests a CVSSv2 vector of AV:N/AC:M/Au:N/C:P/I:P/A:P. The exception is CVE-2013-4002 with a CVSSv2 base score of 7.1.
CVE CVSSv2 Score Fixed in CVE-2013-3006 9.3 7 SR5 CVE-2013-3007 9.3 6.0.1 SR6, 7 SR5 CVE-2013-3008 9.3 7 SR5 CVE-2013-3009 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5 CVE-2013-3010 9.3 6.0.1 SR6, 7 SR5 CVE-2013-3011 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5 CVE-2013-3012 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5 CVE-2013-4002 7.1 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5
References: https://www.ibm.com/developerworks/java/jdk/alerts/ http://www.ibm.com/developerworks/java/jdk/aix/j764/Java764.fixes.html#SR5 http://www.ibm.com/developerworks/java/jdk/aix/j664/Java664.fixes.html#SR14 http://www.ibm.com/developerworks/java/jdk/aix/j564/fixes.html#SR16FP3
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3008.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3006?
CVE-2013-3006 has a CVSSv2 base score of 9.3, indicating high severity.
How do I fix CVE-2013-3006?
To fix CVE-2013-3006, update to the latest version of the IBM JDK as specified by your distribution.
Which versions are affected by CVE-2013-3006?
CVE-2013-3006 affects multiple versions of IBM JDK, including 5.0 SR16-FP3, 6 SR14, and several 7.x versions.
What types of vulnerabilities does CVE-2013-3006 include?
CVE-2013-3006 includes unspecified security flaws that could potentially compromise confidentiality, integrity, and availability.
Is CVE-2013-3006 still a risk in supported environments?
Yes, CVE-2013-3006 remains a risk if affected versions of the IBM JDK are in use without updates.