IBM Java Multiple Remote Code Execution Vulnerabilities
BID:55495
Info
IBM Java Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 55495 |
| Class: | Design Error |
| CVE: |
CVE-2012-4820 CVE-2012-4821 CVE-2012-4822 CVE-2012-4823 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2012 12:00AM |
| Updated: | Oct 24 2013 09:43AM |
| Credit: | Adam Gowdiak of Security Explorations |
| Vulnerable: |
Red Hat Enterprise Linux Workstation Supplementary 6 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Server Supplementary 6 Red Hat Enterprise Linux HPC Node Supplementary 6 Red Hat Enterprise Linux Desktop Supplementary 6 Red Hat Enterprise Linux Desktop Supplementary 5 client IBM WebSphere Application Server for z/OS 7.0.0.23 IBM WebSphere Application Server for z/OS 7.0.0.22 IBM WebSphere Application Server for z/OS 7.0.0.21 IBM WebSphere Application Server for z/OS 7.0.0.20 IBM WebSphere Application Server for z/OS 7.0.0.20 IBM WebSphere Application Server for z/OS 7.0.0.19 IBM WebSphere Application Server for z/OS 7.0.0.18 IBM WebSphere Application Server for z/OS 7.0.0.15 IBM WebSphere Application Server for z/OS 7.0 IBM WebSphere Application Server for z/OS 6.1.0.35 IBM WebSphere Application Server for z/OS 6.1 IBM Websphere Application Server 8.0 2 IBM Websphere Application Server 7.0 3 IBM Websphere Application Server 7.0 21 IBM Websphere Application Server 7.0 .9 IBM Websphere Application Server 7.0 .8 IBM Websphere Application Server 7.0 .2 IBM Websphere Application Server 7.0 .13 IBM Websphere Application Server 7.0 .12 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 6.1 41 IBM Websphere Application Server 6.1 .9 IBM Websphere Application Server 6.1 .8 IBM Websphere Application Server 6.1 .7 IBM Websphere Application Server 6.1 .6 IBM Websphere Application Server 6.1 .5 IBM Websphere Application Server 6.1 .4 IBM Websphere Application Server 6.1 .33 IBM Websphere Application Server 6.1 .32 IBM Websphere Application Server 6.1 .3 IBM Websphere Application Server 6.1 .25 IBM Websphere Application Server 6.1 .23 IBM Websphere Application Server 6.1 .22 IBM Websphere Application Server 6.1 .21 IBM Websphere Application Server 6.1 .20 IBM Websphere Application Server 6.1 .2 IBM Websphere Application Server 6.1 .19 IBM Websphere Application Server 6.1 .18 IBM Websphere Application Server 6.1 .17 IBM Websphere Application Server 6.1 .15 IBM Websphere Application Server 6.1 .14 IBM Websphere Application Server 6.1 .13 IBM Websphere Application Server 6.1 .12 IBM Websphere Application Server 6.1 .11 IBM Websphere Application Server 6.1 .10 IBM Websphere Application Server 6.1 .1 IBM Websphere Application Server 6.1 IBM Websphere Application Server 8.0.0.4 IBM Websphere Application Server 8.0.0.1 IBM Websphere Application Server 8.0.0.0 IBM Websphere Application Server 8.0 IBM Websphere Application Server 7.0.0.23 IBM Websphere Application Server 7.0.0.19 IBM Websphere Application Server 7.0.0.17 IBM Websphere Application Server 7.0.0.15 IBM Websphere Application Server 7.0.0.15 IBM Websphere Application Server 7.0.0.14 IBM Websphere Application Server 7.0.0.13 IBM Websphere Application Server 7.0.0.1 IBM Websphere Application Server 7.0.0.0 IBM Websphere Application Server 7.0 IBM Websphere Application Server 6.1.0.45 IBM Websphere Application Server 6.1.0.43 IBM Websphere Application Server 6.1.0.39 IBM Websphere Application Server 6.1.0.37 IBM Websphere Application Server 6.1.0.35 IBM Websphere Application Server 6.1.0.34 IBM Websphere Application Server 6.1.0.33 IBM Websphere Application Server 6.1.0.33 IBM Websphere Application Server 6.1.0.31 IBM Websphere Application Server 6.1.0.29 IBM Websphere Application Server 6.1.0.27 IBM Websphere Application Server 6.1 IBM Tivoli Monitoring 6.2.3 IBM Tivoli Monitoring 6.2.2 IBM Tivoli Monitoring 6.2.1 IBM Tivoli Monitoring 6.2 IBM Tivoli Management Framework 4.3.1 IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0 IBM OS/400 V6R1M0 IBM OS/400 V5R4M0 IBM Lotus Notes 8.5.3 IBM Lotus Notes 8.5.2 IBM Lotus Notes 8.5.1 IBM Lotus Notes 8.5.1 IBM Lotus Notes 8.0.2 IBM Lotus Notes 8.5.2 FP2 IBM Lotus Notes 8.5.1.3 IBM Lotus Notes 8.5.1.2 IBM Lotus Notes 8.5.1 FP5 IBM Lotus Notes 8.5.0.1 IBM Lotus Notes 8.5 IBM Lotus Notes 8.0.2.1 IBM Lotus Notes 8.0.2.0 IBM Lotus Notes 8.0.2 FP6 IBM Lotus Notes 8.0 IBM Lotus Domino 8.5.3 IBM Lotus Domino 8.5.2 IBM Lotus Domino 8.5.1 Fix Pack 2 IBM Lotus Domino 8.5.1 IBM Lotus Domino 8.5 IBM Lotus Domino 8.0.2 Fix Pack 5 IBM Lotus Domino 8.0.2 IBM Lotus Domino 8.0.1 IBM Lotus Domino 8.5.3FP1 IBM Lotus Domino 8.5.2 FP4 IBM Lotus Domino 8.5.2 FP3 IBM Lotus Domino 8.5.2 FP3 IBM Lotus Domino 8.5.2 FP2 IBM Lotus Domino 8.5.1FP5 IBM Lotus Domino 8.5 FP1 IBM Lotus Domino 8.5 IBM Lotus Domino 8.0.2.1 IBM Lotus Domino 8.0.2 FP4 IBM Lotus Domino 8.0 IBM Java SDK 6 SR10 IBM Java SDK 6 |
| Not Vulnerable: | |
Discussion
IBM Java Multiple Remote Code Execution Vulnerabilities
IBM Java is prone to multiple remote code-execution vulnerabilities in the Java Runtime Environment.
To exploit these issues, an attacker must entice an unsuspecting user into visiting a specially crafted webpage that contains a malicious Applet, or into opening a specially crafted file.
An attacker can exploit these issues to execute arbitrary code and bypass sandbox security feature of Java in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
IBM Java is prone to multiple remote code-execution vulnerabilities in the Java Runtime Environment.
To exploit these issues, an attacker must entice an unsuspecting user into visiting a specially crafted webpage that contains a malicious Applet, or into opening a specially crafted file.
An attacker can exploit these issues to execute arbitrary code and bypass sandbox security feature of Java in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
IBM Java Multiple Remote Code Execution Vulnerabilities
The researcher responsible for discovering these issues has developed an exploit code to trigger the vulnerabilities. This exploit code is not known to be publicly available.
The researcher responsible for discovering these issues has developed an exploit code to trigger the vulnerabilities. This exploit code is not known to be publicly available.
Solution / Fix
IBM Java Multiple Remote Code Execution Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
IBM Java Multiple Remote Code Execution Vulnerabilities
References:
References: