Lucene search

K
cveOracleCVE-2013-2436
HistoryApr 17, 2013 - 6:55 p.m.

CVE-2013-2436

2013-04-1718:55:07
oracle
web.nvd.nist.gov
52
cve-2013-2436
java
jre
oracle
openjdk
remote attack
confidentiality
integrity
availability
libraries
type checks
method handle binding
wrapper.convert
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

High

EPSS

0.968

Percentile

99.7%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-1488 and CVE-2013-2426. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect “type checks” and “method handle binding” involving Wrapper.convert.

Affected configurations

Nvd
Node
oraclejreRange1.7.0update17
OR
oraclejreMatch1.7.0
OR
oraclejreMatch1.7.0update1
OR
oraclejreMatch1.7.0update10
OR
oraclejreMatch1.7.0update11
OR
oraclejreMatch1.7.0update13
OR
oraclejreMatch1.7.0update15
OR
oraclejreMatch1.7.0update2
OR
oraclejreMatch1.7.0update3
OR
oraclejreMatch1.7.0update4
OR
oraclejreMatch1.7.0update5
OR
oraclejreMatch1.7.0update6
OR
oraclejreMatch1.7.0update7
OR
oraclejreMatch1.7.0update9
Node
oraclejdkRange1.7.0update17
OR
oraclejdkMatch1.7.0
OR
oraclejdkMatch1.7.0update1
OR
oraclejdkMatch1.7.0update10
OR
oraclejdkMatch1.7.0update11
OR
oraclejdkMatch1.7.0update13
OR
oraclejdkMatch1.7.0update15
OR
oraclejdkMatch1.7.0update2
OR
oraclejdkMatch1.7.0update3
OR
oraclejdkMatch1.7.0update4
OR
oraclejdkMatch1.7.0update5
OR
oraclejdkMatch1.7.0update6
OR
oraclejdkMatch1.7.0update7
OR
oraclejdkMatch1.7.0update9
VendorProductVersionCPE
oraclejre*cpe:2.3:a:oracle:jre:*:update17:*:*:*:*:*:*
oraclejre1.7.0cpe:2.3:a:oracle:jre:1.7.0:*:*:*:*:*:*:*
oraclejre1.7.0cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*
oraclejre1.7.0cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:*
oraclejre1.7.0cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:*
oraclejre1.7.0cpe:2.3:a:oracle:jre:1.7.0:update13:*:*:*:*:*:*
oraclejre1.7.0cpe:2.3:a:oracle:jre:1.7.0:update15:*:*:*:*:*:*
oraclejre1.7.0cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:*
oraclejre1.7.0cpe:2.3:a:oracle:jre:1.7.0:update3:*:*:*:*:*:*
oraclejre1.7.0cpe:2.3:a:oracle:jre:1.7.0:update4:*:*:*:*:*:*
Rows per page:
1-10 of 281

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

High

EPSS

0.968

Percentile

99.7%