First published: Sun Nov 24 2013(Updated: )
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, 6.0.0 before SR15, and 5.0.0 before SR16 FP4 allows remote attackers to access restricted classes via unspecified vectors related to XML and XSL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM JDK | =5.0.0.0 | |
IBM JDK | =6.0.0.0 | |
IBM JDK | =6.0.1.0 | |
IBM JDK | =7.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5375 is considered a high-severity vulnerability due to potential unauthorized access to restricted classes.
To fix CVE-2013-5375, upgrade your IBM Java SDK to a version that is not affected, such as 7.0.0 SR6 or newer.
CVE-2013-5375 affects IBM Java SDK 5.0.0 before SR16 FP4, 6.0.0 before SR15, 6.0.1 before SR7, and 7.0.0 before SR6.
Exploitation of CVE-2013-5375 could allow remote attackers to access classes that are intended to be restricted, potentially compromising application security.
There are no documented workarounds for CVE-2013-5375, so updating to a patched version is recommended.