---
cve: "CVE-2013-5456"
severity: "LOW"
cvss: 3.1
epss: "6%"
vendor: "n/a"
kev: false
exploited: false
published: "2013-11-24 18:55:04"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T04:47:38+02:00"
---

# CVE-2013-5456

> 3.1 LOW

## Beschreibung

The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.

## Referenzen

- <http://www-01.ibm.com/support/docview.wss?uid=swg1IV51329>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/88255>
- <http://www-01.ibm.com/support/docview.wss?uid=swg21655202>
- <http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00013.html>
- <http://www-01.ibm.com/support/docview.wss?uid=swg21655201>
- <http://www.security-explorations.com/materials/SE-2012-01-IBM-3.pdf>
- <https://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_November_2013>
- <http://rhn.redhat.com/errata/RHSA-2013-1507.html>
- <http://www.security-explorations.com/materials/SE-2012-01-IBM-5.pdf>
- <http://secunia.com/advisories/56338>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2013-5456) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
