Lucene search

K
cve[email protected]CVE-2013-2460
HistoryJun 18, 2013 - 10:55 p.m.

CVE-2013-2460

2013-06-1822:55:02
web.nvd.nist.gov
70
cve-2013-2460
oracle
java
vulnerability
jre
remote attackers
confidentiality
integrity
availability
openjdk
serviceability
bypass
sandbox

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

High

0.968 High

EPSS

Percentile

99.7%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to “insufficient access checks” in the tracing component.

Affected configurations

NVD
Node
oraclejreRange1.7.0update21
OR
oraclejreMatch1.7.0
OR
oraclejreMatch1.7.0update1
OR
oraclejreMatch1.7.0update10
OR
oraclejreMatch1.7.0update11
OR
oraclejreMatch1.7.0update13
OR
oraclejreMatch1.7.0update15
OR
oraclejreMatch1.7.0update17
OR
oraclejreMatch1.7.0update2
OR
oraclejreMatch1.7.0update3
OR
oraclejreMatch1.7.0update4
OR
oraclejreMatch1.7.0update5
OR
oraclejreMatch1.7.0update6
OR
oraclejreMatch1.7.0update7
OR
oraclejreMatch1.7.0update9
Node
oraclejdkRange1.7.0update21
OR
oraclejdkMatch1.7.0
OR
oraclejdkMatch1.7.0update1
OR
oraclejdkMatch1.7.0update10
OR
oraclejdkMatch1.7.0update11
OR
oraclejdkMatch1.7.0update13
OR
oraclejdkMatch1.7.0update15
OR
oraclejdkMatch1.7.0update17
OR
oraclejdkMatch1.7.0update2
OR
oraclejdkMatch1.7.0update3
OR
oraclejdkMatch1.7.0update4
OR
oraclejdkMatch1.7.0update5
OR
oraclejdkMatch1.7.0update6
OR
oraclejdkMatch1.7.0update7
OR
oraclejdkMatch1.7.0update9
CPENameOperatorVersion
oracle:jreoracle jrele1.7.0

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

High

0.968 High

EPSS

Percentile

99.7%