IBM Java CVE-2013-3009 Unspecified Arbitrary Code Execution Vulnerability
BID:61308
Info
IBM Java CVE-2013-3009 Unspecified Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 61308 |
| Class: | Unknown |
| CVE: |
CVE-2013-3009 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 03 2013 12:00AM |
| Updated: | Mar 19 2015 08:33AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Software Development Kit 11 SP3 SuSE SUSE Linux Enterprise Server 11 SP3 for VMware SuSE SUSE Linux Enterprise Server 11 SP3 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise Server 10 SP3 LTSS SuSE SUSE Linux Enterprise Java 11 SP3 SuSE SUSE Linux Enterprise Java 10 SP4 SuSE Suse Linux Enterprise Desktop 10 SP4 S.u.S.E. SUSE CORE 9 for x86 S.u.S.E. CORE 9 IBM WebSphere Real Time 3 SR4-FP2 IBM WebSphere Real Time 2.0 IBM WebSphere Operational Decision Management 7.5.0.0 IBM WebSphere ILOG JRules 7.1 IBM Virtualization Engine TS7700 0 IBM Tivoli System Automation for Integrated Operations Management 2.1.1 IBM Tivoli System Automation for Integrated Operations Management 2.1 IBM Tivoli Storage Productivity Center 5.1.1 IBM Tivoli Storage Productivity Center 5.1 IBM Tivoli Storage Productivity Center 5.1.1.1 IBM Tivoli Storage Productivity Center 5.1.1.0 IBM Tivoli Storage Productivity Center 4.2.2 FP3 IBM Tivoli Storage Productivity Center 4.2.1 Fix Pack 4 IBM Tivoli Storage Productivity Center 4.2.1 IBM Tivoli Storage Productivity Center 4.2.0 IBM Tivoli Storage Productivity Center 4.1 IBM Tivoli Remote Control 5.1.2 IBM Tivoli Monitoring 6.3 IBM Tivoli Monitoring 6.2.3 Fix Pack 3 IBM Tivoli Monitoring 6.2.3 2 IBM Tivoli Monitoring 6.2.3 IBM Tivoli Monitoring 6.2.2 9 IBM Tivoli Monitoring 6.2.2 IBM Tivoli Monitoring 6.2.1 Fix Pack 04 IBM Tivoli Monitoring 6.2.1 IBM Tivoli Monitoring 6.2 Fix Pack 03 IBM Tivoli Monitoring 6.2 IBM Tivoli Monitoring 6.3.0.1 IBM Tivoli Monitoring 6.2.3.1 IBM Tivoli Monitoring 6.2.2 FP6 IBM Tivoli Monitoring 6.2.2 FixPack 4 IBM Tivoli Endpoint Manager for Remote Control 9.0 IBM Tivoli Endpoint Manager for Remote Control 8.2.1 IBM Tivoli Endpoint Manager for Remote Control 8.2 IBM Tivoli Application Dependency Discovery Manager 7.2.2 IBM Tivoli Application Dependency Discovery Manager 7.2.1 3 IBM Tivoli Application Dependency Discovery Manager 7.2.1 2 IBM Tivoli Application Dependency Discovery Manager 7.2.1 1 IBM Tivoli Application Dependency Discovery Manager 7.2.1 IBM Tivoli Application Dependency Discovery Manager 7.2 IBM Tivoli Application Dependency Discovery Manager 7.2.1.5 IBM Tivoli Application Dependency Discovery Manager 7.2.1.4 IBM System Storage Productivity Center 0 IBM Smart Analytics System 5600 9.7 IBM Service Delivery Manager 7.2.4 IBM Service Delivery Manager 7.2.2 IBM Service Delivery Manager 7.2.1 IBM Runtimes for Java Technology 1.4.2 IBM Runtimes for Java Technology 7.0 IBM Runtimes for Java Technology 6.0 IBM Runtimes for Java Technology 5.0 IBM Rational Host On-Demand 11.0 IBM Rational Host On-Demand 11.0.8 IBM OS/400 V6R1M0 IBM OS/400 V5R4M0 IBM Operational Decision Manager 8.5 IBM Operational Decision Manager 8.0 IBM Lotus Notes 8.5.3 IBM Lotus Notes 8.5.2 IBM Lotus Notes 8.5.1 IBM Lotus Notes 8.0.2 IBM Lotus Notes 9.0 IBM Lotus Notes 8.5 IBM Lotus Notes 8.0.0 IBM Lotus Expeditor 6.2.3 IBM Lotus Expeditor 6.2.2 IBM Lotus Expeditor 6.2.1 IBM Lotus Domino 8.5.3 IBM Lotus Domino 8.5.2 IBM Lotus Domino 8.5.1 IBM Lotus Domino 8.0.2 IBM Lotus Domino 8.0.1 IBM Lotus Domino 8.5 IBM Lotus Domino 8.0 IBM Java SDK 7 SR4-FP2 IBM Java SDK 6.0.1 SR5-FP2 IBM Java SDK 6 SR13-FP2 IBM Java SDK 5.0 SR16-FP2 IBM Java SDK 1.4.2 SR13-FP17 IBM i V5R4 IBM i 7.1 IBM i 6.1 IBM Flex System Manager Types 8734 1.3 IBM Flex System Manager Types 8734 1.1.0 IBM Flex System Manager Types 8731 1.3 IBM Flex System Manager Types 8731 1.1.0 IBM Flex System Manager Types 7955 1.3 IBM Flex System Manager Types 7955 1.1.0 IBM Cloudburst 2.1.1 IBM Cloudburst 2.1 IBM Cloudburst 1.2 |
| Not Vulnerable: |
IBM WebSphere Real Time 3 SR5 IBM Virtualization Engine TS7700 8.31.0.89 IBM Tivoli System Automation for Integrated Operations Management 2.1.1.5 IBM Tivoli Storage Productivity Center 5.1.1.2 IBM Tivoli Storage Productivity Center 4.2.2.170 (FP4) IBM Runtimes for Java Technology 7.0.0 SR5 IBM Runtimes for Java Technology 6.0.1 SR6 IBM Runtimes for Java Technology 6 SR14 IBM Runtimes for Java Technology 5.0 SR16-FP3 IBM Runtimes for Java Technology 1.4.2 SR13-FP18 IBM Lotus Notes 8.5.3 Fix Pack 5 IBM Lotus Domino 8.5.3 Fix Pack 4 IBM Java SDK 7 SR5 IBM Java SDK 6.0.1 SR6 IBM Java SDK 6 SR14 IBM Java SDK 5.0 SR16-FP3 IBM Java SDK 1.4.2 SR13-FP18 |
Discussion
IBM Java CVE-2013-3009 Unspecified Arbitrary Code Execution Vulnerability
IBM Java is prone to an unspecified arbitrary code-execution vulnerability.
Limited information is currently available regarding this issue. We will update this BID as more information emerges.
An attacker can leverage this issue to execute arbitrary code within the context of the application.
IBM Java is prone to an unspecified arbitrary code-execution vulnerability.
Limited information is currently available regarding this issue. We will update this BID as more information emerges.
An attacker can leverage this issue to execute arbitrary code within the context of the application.
Exploit / POC
IBM Java CVE-2013-3009 Unspecified Arbitrary Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM Java CVE-2013-3009 Unspecified Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Java CVE-2013-3009 Unspecified Arbitrary Code Execution Vulnerability
References:
References:
- IBM Homepage (IBM)
- IBM SDK for Java 7 32-bit and 64-bit fixes (IBM)
- IBM Security Update July 2013 (IBM)
- IBM Notes & Domino fixes for multiple vulnerabilities in IBM JRE (IBM)
- IBM Tivoli Monitoring clients affected by vulnerabilities in IBM JRE executed un (IBM)
- IBM Tivoli Monitoring clients affected by vulnerabilities in IBM JRE executed un (IBM)
- IBM Tivoli Monitoring clients affected by vulnerabilities in IBM JREexecuted und (IBM)
- IX90118: FIX SECURITY VULNERABILITY CVE-2013-3009 (IBM)
- Multiple vulnerabilities in the IBM i Java SDK (IBM)
- Security Bulletin: Flex System Manager (FSM) ? June 2013 Java Vulnerabilities (IBM)
- Security Bulletin: IBM Endpoint Manager for Remote Control 9.0.0 clients affecte (IBM)
- Security Bulletin: IBM Lotus Expeditor fixes for multiple vulnerabilities in IBM (IBM)
- Security Bulletin: IBM Operational Decision Manager and WebSphere ILOG JRules: M (IBM)
- Security Bulletin: IBM Smart Analytics System 5600 is affected by vulnerabilitie (IBM)
- Security Bulletin: IBM Tivoli System Automation for Integrated Operations Manage (IBM)
- Security Bulletin: IBM Virtualization Engine TS7700 13 Multiple Java CVEs from (IBM)
- Security Bulletin: Multiple IBM SDK Java Technology Edition, Version 6 security (IBM)
- Security Bulletin: Multiple vulnerabilities in IBM WebSphere Real Time (IBM)
- Security Bulletin: Multiple vulnerabilities in the IBM Java SDK (IBM)
- Security Bulletin: Rational Host On-Demand clients affected by vulnerabilities i (IBM)
- Security Bulletin: Tivoli Endpoint Manager for Remote Control 8.2.1 clients affe (IBM)
- Security Bulletin: Tivoli Remote Control 5.1.2 clients affected by vulnerabiliti (IBM)
- Security Bulletin: Tivoli Storage Productivity Center - Oracle CPU June 2013 (IBM)
- Security Bulletin: Tivoli Storage Productivity Center clients affected by vulner (IBM)
- SI50497 - JVA-RUN JDK50-32 IBM Technology for Java SR16 FP3 (IBM)
- SI50498 - JVA-RUN JDK50-32 IBM Technology for Java SR16 FP3 (IBM)
- SI50505 - JVA-RUN JDK50-64 IBM Technology for Java SR16-FP3 (IBM)
- SI50506 - JVA-RUN JDK50-32 IBM Technology for Java SR16-FP3 (IBM)
- TADDM 7.2.2.0 and 7.2.1.5: Vulnerabilities in embedded JRE (IBM)
- Vulnerabilities in IBM Tivoli Monitoring affecting IBM CloudBurst (IBM)
- Vulnerabilities in IBM Tivoli Monitoring affecting IBM Service Delivery Manager (IBM)