CVE-2013-3009 describes a critical vulnerability in IBM Java versions 1.4.2, 5.0, 6, 6.0.1, and 7, where the com.ibm.CORBA.iiop.ClientDelegate class improperly exposes the invoke method, allowing remote attackers to bypass sandbox protections. This flaw enables attackers to call setSecurityManager through an AccessController doPrivileged block. With a CVSS score of 9.3, this vulnerability is highly severe, indicating a network-based attack with medium complexity that can lead to complete compromise of confidentiality, integrity, and availability. Its FAUCET Risk Score of 79/100 further emphasizes its significant risk. While there is no evidence of active exploitation in the KEV catalog or public exploit intelligence platforms like Metasploit or ExploitDB, the vulnerability garnered significant community discussion and media coverage at the time, including articles detailing patch bypasses.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.2CPE matchmatch criteria | cpe:2.3:a:ibm:java:1.4.2:*:*:*:*:*:*:* | ||
1.4.2.13CPE matchmatch criteria | cpe:2.3:a:ibm:java:1.4.2.13:*:*:*:*:*:*:* | ||
1.4.2.13.1CPE matchmatch criteria | cpe:2.3:a:ibm:java:1.4.2.13.1:*:*:*:*:*:*:* | ||
1.4.2.13.2CPE matchmatch criteria | cpe:2.3:a:ibm:java:1.4.2.13.2:*:*:*:*:*:*:* | ||
1.4.2.13.3CPE matchmatch criteria | cpe:2.3:a:ibm:java:1.4.2.13.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.