// For flags

CVE-2013-3009

JDK: Unspecified security fixes (July 2013)

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The com.ibm.CORBA.iiop.ClientDelegate class in IBM Java 1.4.2 before 1.4.2 SR13-FP18, 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 improperly exposes the invoke method of the java.lang.reflect.Method class, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to the AccessController doPrivileged block.

La clase com.ibm.CORBA.iiop.ClientDelegate en IBM Java 1.4.2 en vesiones anteriores a 1.4.2 SR13-FP18, 5.0 en vesiones anteriores a 5.0 SR16-FP3, 6 en vesiones anteriores a 6 SR14, 6.0.1 en vesiones anteriores a 6.0.1 SR6 y 7 en vesiones anteriores a 7 SR5 expone de manera incorrecta el método invocado de la clase java.lang.reflect.Method, lo que permite a atacantes remotos hacer llamar a setSecurityManager y eludir un mecanismo de protección de sandbox a través de vectores relacionados con el bloque AccessController doPrivileged.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-04-12 CVE Reserved
  • 2013-07-23 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (24)
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2
Search vendor "Ibm" for product "Java" and version "1.4.2"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13
Search vendor "Ibm" for product "Java" and version "1.4.2.13"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.1
Search vendor "Ibm" for product "Java" and version "1.4.2.13.1"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.2
Search vendor "Ibm" for product "Java" and version "1.4.2.13.2"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.3
Search vendor "Ibm" for product "Java" and version "1.4.2.13.3"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.4
Search vendor "Ibm" for product "Java" and version "1.4.2.13.4"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.5
Search vendor "Ibm" for product "Java" and version "1.4.2.13.5"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.6
Search vendor "Ibm" for product "Java" and version "1.4.2.13.6"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.7
Search vendor "Ibm" for product "Java" and version "1.4.2.13.7"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.8
Search vendor "Ibm" for product "Java" and version "1.4.2.13.8"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.9
Search vendor "Ibm" for product "Java" and version "1.4.2.13.9"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.10
Search vendor "Ibm" for product "Java" and version "1.4.2.13.10"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.11
Search vendor "Ibm" for product "Java" and version "1.4.2.13.11"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.12
Search vendor "Ibm" for product "Java" and version "1.4.2.13.12"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.13
Search vendor "Ibm" for product "Java" and version "1.4.2.13.13"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.14
Search vendor "Ibm" for product "Java" and version "1.4.2.13.14"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.15
Search vendor "Ibm" for product "Java" and version "1.4.2.13.15"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.16
Search vendor "Ibm" for product "Java" and version "1.4.2.13.16"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
1.4.2.13.17
Search vendor "Ibm" for product "Java" and version "1.4.2.13.17"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
7.0.0.0
Search vendor "Ibm" for product "Java" and version "7.0.0.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
7.0.1.0
Search vendor "Ibm" for product "Java" and version "7.0.1.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
7.0.2.0
Search vendor "Ibm" for product "Java" and version "7.0.2.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
7.0.3.0
Search vendor "Ibm" for product "Java" and version "7.0.3.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
7.0.4.0
Search vendor "Ibm" for product "Java" and version "7.0.4.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
7.0.4.1
Search vendor "Ibm" for product "Java" and version "7.0.4.1"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
7.0.4.2
Search vendor "Ibm" for product "Java" and version "7.0.4.2"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.0.0
Search vendor "Ibm" for product "Java" and version "6.0.0.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.1.0
Search vendor "Ibm" for product "Java" and version "6.0.1.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.2.0
Search vendor "Ibm" for product "Java" and version "6.0.2.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.3.0
Search vendor "Ibm" for product "Java" and version "6.0.3.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.4.0
Search vendor "Ibm" for product "Java" and version "6.0.4.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.5.0
Search vendor "Ibm" for product "Java" and version "6.0.5.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.6.0
Search vendor "Ibm" for product "Java" and version "6.0.6.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.7.0
Search vendor "Ibm" for product "Java" and version "6.0.7.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.8.0
Search vendor "Ibm" for product "Java" and version "6.0.8.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.8.1
Search vendor "Ibm" for product "Java" and version "6.0.8.1"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.9.0
Search vendor "Ibm" for product "Java" and version "6.0.9.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.9.1
Search vendor "Ibm" for product "Java" and version "6.0.9.1"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.9.2
Search vendor "Ibm" for product "Java" and version "6.0.9.2"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.10.0
Search vendor "Ibm" for product "Java" and version "6.0.10.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.10.1
Search vendor "Ibm" for product "Java" and version "6.0.10.1"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.11.0
Search vendor "Ibm" for product "Java" and version "6.0.11.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.12.0
Search vendor "Ibm" for product "Java" and version "6.0.12.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.13.0
Search vendor "Ibm" for product "Java" and version "6.0.13.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.13.1
Search vendor "Ibm" for product "Java" and version "6.0.13.1"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
6.0.13.2
Search vendor "Ibm" for product "Java" and version "6.0.13.2"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.0.0
Search vendor "Ibm" for product "Java" and version "5.0.0.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.11.0
Search vendor "Ibm" for product "Java" and version "5.0.11.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.11.1
Search vendor "Ibm" for product "Java" and version "5.0.11.1"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.11.2
Search vendor "Ibm" for product "Java" and version "5.0.11.2"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.12.0
Search vendor "Ibm" for product "Java" and version "5.0.12.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.12.1
Search vendor "Ibm" for product "Java" and version "5.0.12.1"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.12.2
Search vendor "Ibm" for product "Java" and version "5.0.12.2"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.12.3
Search vendor "Ibm" for product "Java" and version "5.0.12.3"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.12.4
Search vendor "Ibm" for product "Java" and version "5.0.12.4"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.12.5
Search vendor "Ibm" for product "Java" and version "5.0.12.5"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.13.0
Search vendor "Ibm" for product "Java" and version "5.0.13.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.14.0
Search vendor "Ibm" for product "Java" and version "5.0.14.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.15.0
Search vendor "Ibm" for product "Java" and version "5.0.15.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.16.0
Search vendor "Ibm" for product "Java" and version "5.0.16.0"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.16.1
Search vendor "Ibm" for product "Java" and version "5.0.16.1"
-
Affected
Ibm
Search vendor "Ibm"
Java
Search vendor "Ibm" for product "Java"
5.0.16.2
Search vendor "Ibm" for product "Java" and version "5.0.16.2"
-
Affected