vendor:
IBM Java
by:
7.5
CVSS
HIGH
Security Bypass
CWE
Product Name: IBM Java
Affected Version From: Versions prior to IBM Java SDK 1.4.2 SR13-FP6, Java SE 5.0.0-SR12, and Java SE 6.0.0-SR9
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:ibm:java_sdk
Platforms Tested:
IBM Java Security Bypass Vulnerability
IBM Java is prone to a security-bypass vulnerability because it fails to sufficiently sanitize user-supplied input. Successful exploits can allow attackers to bypass filtering mechanisms; this may aid in further attacks.
Mitigation:
Update to IBM Java SDK 1.4.2 SR13-FP6, Java SE 5.0.0-SR12, or Java SE 6.0.0-SR9 or later versions.