Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM SDK, Java Technology Edition 输入验证错误漏洞
Vulnerability Description
IBM SDK, Java Technology Edition是美国IBM公司的一款用于Java应用程序开发的软件开发工具包。ecto是elixir-ecto开源的一个用于数据映射和语言集成查询的工具包。 IBM SDK, Java Technology Edition中的com.ibm.CORBA.iiop.ClientDelegate类存在输入验证错误漏洞,该漏洞源于程序调用AccessController doPrivileged块中的‘java.lang.reflect’方法。远程攻击者可利用该
CVSS Information
N/A
Vulnerability Type
N/A