IBM Java Multiple Vulnerabilities
RISK: Medium Risk
TYPE: Operating Systems - Application Platforms
Multiple vulnerabilities have been identified in IBM Java, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.
Some errors in the "invoke()" (java.lang.reflect.Method), "getDeclaredMethods()" (java.lang.Class), "setAccessible()" (java.lang.reflect.AccessibleObject), "defineClass()" (java.lang.ClassLoder) methods, and unspecified methods within the "java.lang.class" class can be exploited to bypass the sandbox.
Successful exploitation of the vulnerabilities may allow execution of arbitrary Java code.
Impact
- Remote Code Execution
- Security Restriction Bypass
System / Technologies affected
- Java 7 SR2 and earlier
- Java 6.0.1 SR3 and earlier
- Java 6 SR11 and earlier
- Java 5 SR14 and earlier
- Java 1.4.2 SR13-FP13 and earlier
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 7 SR3, 6.0.1 SR4, 6 SR12, 5 SR15, or 1.4.2 SR13-FP14.
Vulnerability Identifier
Source
Related Link
Share with