Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Very Low
CVE-2019-4473
Disclosure Date: August 05, 2019 (last updated November 27, 2024)
Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984.
1
Attacker Value
Unknown
CVE-2018-1417
Disclosure Date: February 22, 2018 (last updated November 26, 2024)
Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manager to elevate its privileges. IBM X-Force ID: 138823.
0
Attacker Value
Unknown
CVE-2014-3068
Disclosure Date: December 02, 2014 (last updated October 05, 2023)
IBM Java Runtime Environment (JRE) 7 R1 before SR1 FP1 (7.1.1.1), 7 before SR7 FP1 (7.0.7.1), 6 R1 before SR8 FP1 (6.1.8.1), 6 before SR16 FP1 (6.0.16.1), and before 5.0 SR16 FP7 (5.0.16.7) allows attackers to obtain the private key from a Certificate Management System (CMS) keystore via a brute force attack.
0
Attacker Value
Unknown
CVE-2014-3065
Disclosure Date: December 02, 2014 (last updated October 05, 2023)
Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 before SR16 FP2 (6.0.16.2), and before SR16 FP8 (5.0.16.8) allows local users to execute arbitrary code via vectors related to the shared classes cache.
0
Attacker Value
Unknown
CVE-2014-0878
Disclosure Date: May 26, 2014 (last updated October 05, 2023)
The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and 7R1 before Service Refresh 1 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output.
0
Attacker Value
Unknown
CVE-2013-0485
Disclosure Date: January 21, 2014 (last updated October 05, 2023)
Unspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR13-FP16 has unknown impact and attack vectors related to Class Libraries.
0
Attacker Value
Unknown
CVE-2013-5375
Disclosure Date: November 24, 2013 (last updated October 05, 2023)
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, 6.0.0 before SR15, and 5.0.0 before SR16 FP4 allows remote attackers to access restricted classes via unspecified vectors related to XML and XSL.
0
Attacker Value
Unknown
CVE-2013-5456
Disclosure Date: November 24, 2013 (last updated October 05, 2023)
The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.
0
Attacker Value
Unknown
CVE-2013-5458
Disclosure Date: November 24, 2013 (last updated October 05, 2023)
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-5457
Disclosure Date: November 24, 2013 (last updated October 05, 2023)
Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to execute arbitrary code via unspecified vectors.
0