The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "6.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.0-sp4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.0-sp1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.0-sp2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.0-sp3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "11.0-sp4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.0-sp1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5"
}
]
},
{
"events": [
{
"introduced": "6.0.0.0"
},
{
"fixed": "6.0.16.25"
}
]
},
{
"events": [
{
"introduced": "6.1.0.0"
},
{
"fixed": "6.1.8.25"
}
]
},
{
"events": [
{
"introduced": "7.0.0.0"
},
{
"fixed": "7.0.9.40"
}
]
},
{
"events": [
{
"introduced": "7.1.0.0"
},
{
"fixed": "7.1.3.40"
}
]
},
{
"events": [
{
"introduced": "8.0.0.0"
},
{
"fixed": "8.0.3.0"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0363.json"