Vulnerability detail
Enriched intelligence for a single CVE
Low
CVE-2013-2423
PUBLISHEDUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote...
- Vendor
- Oracle
- Product
- Java SE
- Published
- Apr 17, 2013
- EPSS
- —
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.
CVSS scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitation status
Exploited in the wild
Recorded 2022-05-25 00:00:00 UTC · Source
SSVC decision points
- Exploitation
- active
- Automatable
- No
- Technical impact
- partial
References
- http://security.gentoo.org/glsa/glsa-201406-32.xml
- http://weblog.ikvm.net/PermaLink.aspx?guid=acd2dd6d-1028-4996-95df-efa42ac237f0
- http://www.us-cert.gov/ncas/alerts/TA13-107A
- https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0130
- http://rhn.redhat.com/errata/RHSA-2013-0757.html
- http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/b453d9be6b3f
- http://www.exploit-db.com/exploits/24976
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:161
- http://lists.opensuse.org/opensuse-updates/2013-06/msg00099.html
- http://rhn.redhat.com/errata/RHSA-2013-0752.html
- http://www.ubuntu.com/usn/USN-1806-1
- http://blog.spiderlabs.com/2013/04/java-is-so-confusing.html
- https://bugzilla.redhat.com/show_bug.cgi?id=952398
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16700
- http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
- http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | May 25, 2022 |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/java_jre17_reflection_types.rb | Apr 28, 2025 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Detected by Metasploit