CVE-2013-3009: Critical severity IBM Java vulnerability
The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 improperly exposes the invoke method of the java.lang.reflect.Method class, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to the AccessController doPrivileged block.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2013-3009?
The severity of CVE-2013-3009 is rated as a high vulnerability, allowing remote code execution.
How do I fix CVE-2013-3009?
To fix CVE-2013-3009, update to the appropriate version of IBM Java specified in the remediation list.
What versions of IBM Java are affected by CVE-2013-3009?
CVE-2013-3009 affects IBM Java versions before 1.4.2 SR13-FP18, 5.0 SR16-FP3, 6 SR14, and 7 SR5.
Is CVE-2013-3009 a remote vulnerability?
Yes, CVE-2013-3009 allows attackers to exploit the vulnerability remotely.
What can attackers do with CVE-2013-3009?
Attackers can leverage CVE-2013-3009 to perform remote method invocation, potentially leading to unauthorized actions on the affected systems.