Lucene search

K
cveOracleCVE-2013-2423
HistoryApr 17, 2013 - 6:55 p.m.

CVE-2013-2423

2013-04-1718:55:07
oracle
web.nvd.nist.gov
982
In Wild
2
cve-2013-2423
java runtime environment
jre
oracle
openjdk
remote attackers
integrity
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

8

Confidence

High

EPSS

0.967

Percentile

99.7%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

Affected configurations

Nvd
Node
oraclejreMatch1.7.0-
OR
oraclejreMatch1.7.0update1
OR
oraclejreMatch1.7.0update10
OR
oraclejreMatch1.7.0update11
OR
oraclejreMatch1.7.0update13
OR
oraclejreMatch1.7.0update15
OR
oraclejreMatch1.7.0update2
OR
oraclejreMatch1.7.0update3
OR
oraclejreMatch1.7.0update4
OR
oraclejreMatch1.7.0update5
OR
oraclejreMatch1.7.0update6
OR
oraclejreMatch1.7.0update7
OR
oraclejreMatch1.7.0update9
Node
canonicalubuntu_linuxMatch12.10
OR
opensuseopensuseMatch12.3
VendorProductVersionCPE
oraclejre1.7.0cpe:/a:oracle:jre:1.7.0:update4::
oraclejre1.7.0cpe:/a:oracle:jre:1.7.0:update10::
oraclejre1.7.0cpe:/a:oracle:jre:1.7.0:update3::
oraclejre1.7.0cpe:/a:oracle:jre:1.7.0:update15::
oraclejre1.7.0cpe:/a:oracle:jre:1.7.0:update7::
oraclejre1.7.0cpe:/a:oracle:jre:1.7.0:update5::
oraclejre1.7.0cpe:/a:oracle:jre:1.7.0:update13::
oraclejre1.7.0cpe:/a:oracle:jre:1.7.0:-::
oraclejre1.7.0cpe:/a:oracle:jre:1.7.0:update1::
oraclejre1.7.0cpe:/a:oracle:jre:1.7.0:update11::
Rows per page:
1-10 of 131

References

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

8

Confidence

High

EPSS

0.967

Percentile

99.7%