CVE-2013-2423

Confirmed PUBLISHED

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote...

Oracle · Java SE
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
3.7 Low

At a Glance

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

metasploit java cisa
CVE Published
Apr 17, 2013
Exploitation Reported
May 25, 2022
CVSS
3.7 Low
EPSS
Remote No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • GLSA-201406-32 security.gentoo.org · Vendor Advisory http://security.gentoo.org/glsa/glsa-201406-32.xml
  • RHSA-2013:0757 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2013-0757.html
  • MDVSA-2013:161 mandriva.com · Vendor Advisory http://www.mandriva.com/security/advisories?name=MDVSA-2013:161
  • openSUSE-SU-2013:0964 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-updates/2013-06/msg00099.html
  • RHSA-2013:0752 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2013-0752.html
Show 11 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.