KEVIntel
3.7
CVSS
Low

CVE-2013-2423

PUBLISHED

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote...

Exploited in the wild Remote No user interaction
Vendor
Oracle
Product
Java SE
Published
Apr 17, 2013
EPSS

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

java cisa metasploit

CVSS scores

CVSS v3.1 3.7 Low

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CVSS v2.0 4.3

AV:N/AC:M/Au:N/C:N/I:P/A:N

Exploitation status

Exploited in the wild

Recorded 2022-05-25 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA May 25, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

java_jre17_reflection_types

metasploit · Created Unknown

Metasploit module for CVE-2013-2423

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Metasploit