CVE-2013-4041
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
Unspecified vulnerability in IBM Java SDK 5.0.0 before SR16 FP4, 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to access restricted classes via unspecified vectors.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21655202
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21655201
References
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00013.html
- http://rhn.redhat.com/errata/RHSA-2013-1507.html
- http://rhn.redhat.com/errata/RHSA-2013-1508.html
- http://rhn.redhat.com/errata/RHSA-2013-1509.html
- http://rhn.redhat.com/errata/RHSA-2013-1793.html
- http://secunia.com/advisories/56338
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV51087
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV51088
- http://www-01.ibm.com/support/docview.wss?uid=swg21655201
- http://www-01.ibm.com/support/docview.wss?uid=swg21655202
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86416
- https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00013.html
- http://rhn.redhat.com/errata/RHSA-2013-1507.html
- http://rhn.redhat.com/errata/RHSA-2013-1508.html
- http://rhn.redhat.com/errata/RHSA-2013-1509.html
- http://rhn.redhat.com/errata/RHSA-2013-1793.html
- http://secunia.com/advisories/56338
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV51087
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV51088
- http://www-01.ibm.com/support/docview.wss?uid=swg21655201
- http://www-01.ibm.com/support/docview.wss?uid=swg21655202
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86416
- https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013
Verify integrity in audit chain (admin only). AS-IS.