CVE-2013-5456: Critical severity ibm jdk vulnerability
An unspecified Java sandbox bypass issue in the ORB component was fixed in IBM JDK 7 SR6. This issue got the following CVSSv2 score upstream: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
https://www.ibm.com/developerworks/java/jdk/alerts/#IBMSecurityUpdateNovember2013 https://www.ibm.com/developerworks/java/jdk/aix/j732/Java7.fixes.html#SR6
Further info is available in this WebSphere Real Time security bulletin:
http://www-01.ibm.com/support/docview.wss?uid=swg21655202&myns=swgws&mynp=OCSSSTCZ&mync=R
CVE-2013-5456, CVE-2013-5457 and CVE-2013-5458 allow code running under a security manager to escalate its privileges by modifying or removing the security manager.
Additional details may become available under this X-Force database article:
http://xforce.iss.net/xforce/xfdb/88255
Other sources
The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5456?
CVE-2013-5456 has a CVSSv2 score of 9.3, indicating a critical security vulnerability.
How do I fix CVE-2013-5456?
To mitigate CVE-2013-5456, update to IBM JDK 7 SR6 or later versions as specified in the security advisories.
Which versions of IBM JDK are affected by CVE-2013-5456?
IBM JDK 7.0.0.0 is affected by CVE-2013-5456.
Is CVE-2013-5456 a Java sandbox issue?
Yes, CVE-2013-5456 is an unspecified Java sandbox bypass vulnerability.
What components are involved in CVE-2013-5456?
CVE-2013-5456 specifically impacts the ORB component in IBM's Java implementation.