CVE-2014-3086
Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 before Service Refresh 7 FP1 and other products, allows remote attackers to gain privileges by leveraging the ability to execute code in the context of a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 before Service Refresh 7 FP1 and other products, allows remote attackers to gain privileges by leveraging the ability to execute code in the context of a security manager.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.05% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- ibm/lotus notes · ibm/lotus domino · ibm/websphere real time
- Source
- psirt@us.ibm.com
References
- http://secunia.com/advisories/59680
- http://secunia.com/advisories/60081
- http://secunia.com/advisories/60317
- http://secunia.com/advisories/60622
- http://secunia.com/advisories/61577
- http://secunia.com/advisories/61640
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV62634Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21680333Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21680334
- http://www-01.ibm.com/support/docview.wss?uid=swg21686383
- http://www-01.ibm.com/support/docview.wss?uid=swg21686824
- http://www.securityfocus.com/bid/69183
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94097
- http://secunia.com/advisories/59680
- http://secunia.com/advisories/60081
- http://secunia.com/advisories/60317
- http://secunia.com/advisories/60622
- http://secunia.com/advisories/61577
- http://secunia.com/advisories/61640
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV62634Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21680333Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21680334
- http://www-01.ibm.com/support/docview.wss?uid=swg21686383
- http://www-01.ibm.com/support/docview.wss?uid=swg21686824
- http://www.securityfocus.com/bid/69183
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94097
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.