CVE-2016-0376
Summary
| CVE | CVE-2016-0376 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-06-03 14:59:00 UTC |
| Updated | 2023-09-12 14:55:00 UTC |
| Description | The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Java Sdk | All | All | All | All |
| Application | Ibm | Java Sdk | All | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Module For Legacy Software | 12 | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Module For Legacy Software | 12 | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 11.0 | sp2 | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 11.0 | sp3 | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 11.0 | sp4 | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 12.0 | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 12.0 | sp1 | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 11.0 | sp2 | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 11.0 | sp3 | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 11.0 | sp4 | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 12.0 | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Server | 12.0 | sp1 | All | All |
| Application | Novell | Suse Linux Enterprise Software Development Kit | 11.0 | sp4 | All | All |
| Application | Novell | Suse Linux Enterprise Software Development Kit | 12.0 | All | All | All |
| Application | Novell | Suse Linux Enterprise Software Development Kit | 12.0 | sp1 | All | All |
| Operating System | Novell | Suse Linux Enterprise Software Development Kit | 11.0 | sp4 | All | All |
| Operating System | Novell | Suse Linux Enterprise Software Development Kit | 12.0 | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Software Development Kit | 12.0 | sp1 | All | All |
| Operating System | Novell | Suse Linux Enterprise Software Development Kit | 11.0 | sp4 | All | All |
| Operating System | Novell | Suse Linux Enterprise Software Development Kit | 12.0 | All | All | All |
| Operating System | Novell | Suse Linux Enterprise Software Development Kit | 12.0 | sp1 | All | All |
| Operating System | Novell | Suse Manager | 2.1 | All | All | All |
| Operating System | Novell | Suse Manager | 2.1 | All | All | All |
| Operating System | Novell | Suse Manager Proxy | 2.1 | All | All | All |
| Operating System | Novell | Suse Manager Proxy | 2.1 | All | All | All |
| Operating System | Novell | Suse Openstack Cloud | 5 | All | All | All |
| Operating System | Novell | Suse Openstack Cloud | 5 | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 5.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 5.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Desktop | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Hpc Node Supplementary | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Hpc Node Supplementary | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Hpc Node Supplementary | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Hpc Node Supplementary | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Eus | 6.7 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Eus | 7.2 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Eus | 7.3 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Eus | 7.4 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Eus | 7.5 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Eus | 6.7 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Eus | 7.2 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Eus | 7.3 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Eus | 7.4 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Eus | 7.5 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 5.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 5.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 7.0 | All | All | All |
| Application | Redhat | Satellite | 5.6 | All | All | All |
| Application | Redhat | Satellite | 5.7 | All | All | All |
| Application | Redhat | Satellite | 5.6 | All | All | All |
| Application | Redhat | Satellite | 5.7 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] SUSE-SU-2016:1299-1: important: Security update for | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| IBM IX90171: FIX SECURITY VULNERABILITY CVE-2016-0376 - United States | AIXAPAR | www-01.ibm.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | Third Party Advisory |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | Third Party Advisory |
| IBM Security Bulletin: Multiple vulnerabilities in current releases of the IBM® SDK, Java™ Technology Edition - United States | CONFIRM | www-01.ibm.com | Vendor Advisory |
| [security-announce] SUSE-SU-2016:1300-1: important: Security update for | SUSE | lists.opensuse.org | Third Party Advisory |
| [security-announce] SUSE-SU-2016:1475-1: important: Security update for | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| [security-announce] SUSE-SU-2016:1303-1: important: Security update for | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | Third Party Advisory |
| [security-announce] SUSE-SU-2016:1379-1: important: Security update for | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| IBM Java SDK Bugs Let Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | Third Party Advisory, VDB Entry |
| IBM Java SDK CVE-2016-0376 Incomplete Fix Arbitrary Code Execution Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| [security-announce] SUSE-SU-2016:1458-1: important: Security update for | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| [security-announce] SUSE-SU-2016:1378-1: important: Security update for | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| Full Disclosure: [SE-2012-01] Yet another broken security fix in IBM Java 7/8 | FULLDISC | seclists.org | Mailing List, Third Party Advisory, VDB Entry |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| [security-announce] SUSE-SU-2016:1388-1: important: Security update for | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| Security Explorations | MISC | www.security-explorations.com | Third Party Advisory, VDB Entry |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | Third Party Advisory |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.