Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2013-5456

Disclosure Date: November 24, 2013
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

Technical Analysis