Skip to main content

IBM Java Multiple Vulnerabilities

Last Update Date: 15 Nov 2012 10:25 Release Date: 15 Nov 2012 4361 Views

RISK: Medium Risk

TYPE: Operating Systems - Application Platforms

TYPE: Application Platforms

Multiple vulnerabilities have been identified in IBM Java, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.

 

Some errors in the "invoke()" (java.lang.reflect.Method), "getDeclaredMethods()" (java.lang.Class), "setAccessible()" (java.lang.reflect.AccessibleObject), "defineClass()" (java.lang.ClassLoder) methods, and unspecified methods within the "java.lang.class" class can be exploited to bypass the sandbox.

 

Successful exploitation of the vulnerabilities may allow execution of arbitrary Java code.


Impact

  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • Java 7 SR2 and earlier
  • Java 6.0.1 SR3 and earlier
  • Java 6 SR11 and earlier
  • Java 5 SR14 and earlier
  • Java 1.4.2 SR13-FP13 and earlier

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 7 SR3, 6.0.1 SR4, 6 SR12, 5 SR15, or 1.4.2 SR13-FP14.

Vulnerability Identifier


Source


Related Link