CVE-2013-5458: Critical severity ibm jdk vulnerability
An unspecified Java sandbox bypass issue in the XML component was fixed in IBM JDK 7 SR6. This issue got the following CVSSv2 score upstream: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
https://www.ibm.com/developerworks/java/jdk/alerts/#IBMSecurityUpdateNovember2013 https://www.ibm.com/developerworks/java/jdk/aix/j732/Java7.fixes.html#SR6
Further info is available in this WebSphere Real Time security bulletin:
http://www-01.ibm.com/support/docview.wss?uid=swg21655202&myns=swgws&mynp=OCSSSTCZ&mync=R
CVE-2013-5456, CVE-2013-5457 and CVE-2013-5458 allow code running under a security manager to escalate its privileges by modifying or removing the security manager.
Additional details may become available under this X-Force database article:
http://xforce.iss.net/xforce/xfdb/88257
Other sources
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5458?
CVE-2013-5458 has a CVSSv2 score of 9.3, indicating a critical severity level.
How do I fix CVE-2013-5458?
To fix CVE-2013-5458, upgrade to IBM JDK 7 SR6 or later versions as specified in the remedy details.
What systems are affected by CVE-2013-5458?
CVE-2013-5458 affects IBM JDK 7.0.0.0 and specific versions of the IBM Java package from Red Hat.
What are the potential impacts of CVE-2013-5458?
CVE-2013-5458 could allow attackers to bypass the Java sandbox, leading to possible unauthorized access to sensitive data.
Is there a known workaround for CVE-2013-5458?
There are no direct workarounds for CVE-2013-5458; the best action is to apply the necessary updates.