5

CVE-2013-0431

Warnung
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Jre Version 1.7.0 Update -
Oracle ≫ Jre Version 1.7.0 Update update1
Oracle ≫ Jre Version 1.7.0 Update update10
Oracle ≫ Jre Version 1.7.0 Update update11
Oracle ≫ Jre Version 1.7.0 Update update2
Oracle ≫ Jre Version 1.7.0 Update update3
Oracle ≫ Jre Version 1.7.0 Update update4
Oracle ≫ Jre Version 1.7.0 Update update5
Oracle ≫ Jre Version 1.7.0 Update update6
Oracle ≫ Jre Version 1.7.0 Update update7
Oracle ≫ Jre Version 1.7.0 Update update9
Oracle ≫ Openjdk Version 7 Update -

25.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Oracle JRE Sandbox Bypass Vulnerability

Schwachstelle

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 89.99% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CISA-ADP 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-693 Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

http://security.gentoo.org/glsa/glsa-201406-32.xml
Third Party Advisory
http://arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/
Third Party Advisory
http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53
Not Applicable
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html
Third Party Advisory
http://marc.info/?l=bugtraq&m=136439120408139&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=136733161405818&w=2
Third Party Advisory
Mailing List
http://www.informationweek.com/security/application-security/java-hacker-uncovers-two-flaws-in-latest/240146717
Broken Link
http://www.kb.cert.org/vuls/id/858729
Third Party Advisory
US Government Resource
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Vendor Advisory
http://www.securityfocus.com/archive/1/525387/30/0/threaded
Third Party Advisory
VDB Entry
http://rhn.redhat.com/errata/RHSA-2013-0237.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0247.html
Third Party Advisory
http://seclists.org/fulldisclosure/2013/Jan/142
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2013/Jan/195
Third Party Advisory
Mailing List
http://www.mandriva.com/security/advisories?name=MDVSA-2013:095
Not Applicable
http://www.us-cert.gov/cas/techalerts/TA13-032A.html
Third Party Advisory
US Government Resource
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16579
Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19418
Broken Link
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0431
US Government Resource