← Vulnerability feed

Vulnerability record · CVE-2016-0363 · published 3 June 2016

CVE-2016-0363: Redhat satellite improper input validation vulnerability

Redhat · Satellite

The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.

8.1 CVSS 3.0 High EPSS 4.0% · top 9.9% CWE-20 · Improper input validation
8.1CVSS 3.0 base score, v2 6.8
4.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
44References
17 Jun 2026Last modified by NVD

Description

The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html Mailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0701.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0702.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0708.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0716.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-1039.html Third Party Advisory
http://seclists.org/fulldisclosure/2016/Apr/20 Mailing ListThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2016/Apr/3 Mailing ListThird Party AdvisoryVDB Entry
http://www-01.ibm.com/support/docview.wss?uid=swg1IX90172 Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21980826 Vendor Advisory
http://www.security-explorations.com/materials/SE-2012-01-IBM-4.pdf Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/85895 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1035953 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2016:1430 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1216 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00039.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00040.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00042.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00058.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00059.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00061.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00067.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00002.html Mailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0701.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0702.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0708.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0716.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-1039.html Third Party Advisory
http://seclists.org/fulldisclosure/2016/Apr/20 Mailing ListThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2016/Apr/3 Mailing ListThird Party AdvisoryVDB Entry
http://www-01.ibm.com/support/docview.wss?uid=swg1IX90172 Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21980826 Vendor Advisory
http://www.security-explorations.com/materials/SE-2012-01-IBM-4.pdf Third Party AdvisoryVDB Entry

Track CVE-2016-0363 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-2740Mozilla thunderbird memory buffer overflow vulnerabilityBuffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 3…EPSS 5.6%10.0CVE-2015-2739Mozilla firefox memory buffer overflow vulnerabilityThe ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.…EPSS 2.7%10.0CVE-2015-2733Mozilla firefox vulnerabilityUse-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x be…EPSS 6.2%10.0CVE-2015-2726Oracle solaris memory buffer overflow vulnerabilityMultiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0 allow remote attackers to cause a denial of service (memory…EPSS 6.1%10.0CVE-2015-2725Novell suse linux enterprise software development kit memory buffer overflow vulnerabilityMultiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 …EPSS 6.1%10.0CVE-2015-2724Oracle solaris memory buffer overflow vulnerabilityMultiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thu…EPSS 5.9%10.0CVE-2015-2722Oracle solaris vulnerabilityUse-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x be…EPSS 6.2%10.0CVE-2014-8891Ibm java sdk vulnerabilityUnspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR…EPSS 7.2%

Source: NIST National Vulnerability Database (record CVE-2016-0363), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.