Lucene search

K
cve[email protected]CVE-2013-5884
HistoryJan 15, 2014 - 4:11 p.m.

CVE-2013-5884

2014-01-1516:11:05
web.nvd.nist.gov
52
cve-2013-5884
oracle
java se
vulnerability
corba
remote attackers
confidentiality

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

4.5 Medium

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.4%

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality via vectors related to CORBA. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to an incorrect check for code permissions by CORBA stub factories.

Affected configurations

NVD
Node
oraclejreMatch1.7.0update45
Node
oraclejdkMatch1.5.0update55
OR
oraclejreMatch1.5.0update55
Node
oraclejdkMatch1.6.0update65
OR
oraclejreMatch1.6.0update65
CPENameOperatorVersion
oracle:jreoracle jreeq1.7.0

References

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

4.5 Medium

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.4%