CVE-2016-0363: IBM Java SDK
High severity, CVSS 8.1. EPSS: 4% chance of exploitation in the next 30 days.
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.
Affected products
- IBM Java SDK: from 6.0.0.0, before 6.0.16.25 (fixed in 6.0.16.25); from 6.1.0.0, before 6.1.8.25 (fixed in 6.1.8.25); from 7.0.0.0, before 7.0.9.40 (fixed in 7.0.9.40); from 7.1.0.0, before 7.1.3.40 (fixed in 7.1.3.40); from 8.0.0.0, before 8.0.3.0 (fixed in 8.0.3.0)
- Novell Suse Linux Enterprise Module For Legacy Software: version 12 only
- Novell Suse Linux Enterprise Server: version 11.0 only; version 12.0 only
- Novell Suse Linux Enterprise Software Development Kit: version 11.0 only; version 12.0 only
- Novell Suse Manager: version 2.1 only
- Novell Suse Manager Proxy: version 2.1 only
- Novell Suse Openstack Cloud: version 5 only
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Hpc Node Supplementary: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Eus: version 6.7 only; version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
- Red Hat Satellite: version 5.6 only; version 5.7 only
Published 2016-06-03. Last modified 2026-06-17.