CVE-2016-0376

Severity

51%

Complexity

49%

Confidentiality

106%

CWE-502: Deserialization of Untrusted Data

The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.

CWE-502: Deserialization of Untrusted Data

CVSS 3.0 Base Score 8.1. CVSS Attack Vector: network. CVSS Attack Complexity: high. CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS 2.0 Base Score 5.1. CVSS Attack Vector: network. CVSS Attack Complexity: high. CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:P).

Overview

First reported 8 years ago

2016-06-03 14:59:00

Last updated 5 years ago

2019-06-24 16:48:00

Affected Software

Novell SUSE Linux Enterprise Module For Legacy Software 12

12

Novell SUSE Linux Enterprise Server 11.0 Service Pack 2 Long Term Service Pack Support

11.0

Novell SUSE Linux Enterprise Server 11.0 Service Pack 3 Long Term Service Pack Support

11.0

Novell SUSE Linux Enterprise Server 12.0

12.0

Novell SUSE Linux Enterprise Server 12.0 Service Pack 1

12.0

Novell SUSE Linux Enterprise Software Development Kit 11.0 Service Pack 4

11.0

Novell SUSE Linux Enterprise Software Development Kit 12.0 Service Pack 1

12.0

Novell SUSE Manager 2.1

2.1

Novell SUSE Manager Proxy 2.1

2.1

Novell SUSE OpenStack Cloud 5

5

Red Hat Satellite 5.6

5.6

Red Hat Satellite 5.7

5.7

Red Hat Desktop 5.0

5.0

Red Hat Enterprise Linux Desktop 6.0

6.0

RedHat Enterprise Linux Desktop 7.0

7.0

Red Hat Enterprise Linux Server 6.0

6.0

RedHat Enterprise Linux Server 7.0

7.0

Red Hat Enterprise Linux Server EUS 7.2

7.2

Red Hat Enterprise Linux Server Extended Update Support (EUS) 7.3

7.3

Red Hat Enterprise Linux Server Extended Update Support (EUS) 7.4

7.4

Red Hat Enterprise Linux Server Extended Update Support (EUS) 7.5

7.5

Red Hat Enterprise Linux Workstation 6.0

6.0

RedHat Enterprise Linux Workstation 7.0

7.0

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.