The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes & Domino, Tivoli Storage Productivity Center, and Service Deliver Manager; and other products from other vendors such as Red Hat, allow remote attackers to execute arbitrary code via "insecure use" of the (1) java.lang.Class getDeclaredMethods or nd (2) java.lang.reflect.AccessibleObject setAccessible() methods.
cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:* versions from 1.4.2 to 18.104.22.168.13 (inclusive)
cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:* versions from 22.214.171.124 to 126.96.36.199 (inclusive)
cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:* versions from 188.8.131.52 to 184.108.40.206 (inclusive)
cpe:2.3:a:ibm:java:*:*:*:*:*:*:*:* versions from 220.127.116.11 to 18.104.22.168 (inclusive)