5.3

CVE-2013-0431

Warning

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.

Data is provided by the National Vulnerability Database (NVD)
OracleJre Version1.7.0 Update-
OracleJre Version1.7.0 Updateupdate1
OracleJre Version1.7.0 Updateupdate10
OracleJre Version1.7.0 Updateupdate11
OracleJre Version1.7.0 Updateupdate2
OracleJre Version1.7.0 Updateupdate3
OracleJre Version1.7.0 Updateupdate4
OracleJre Version1.7.0 Updateupdate5
OracleJre Version1.7.0 Updateupdate6
OracleJre Version1.7.0 Updateupdate7
OracleJre Version1.7.0 Updateupdate9
OracleOpenjdk Version7 Update-

25.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Oracle JRE Sandbox Bypass Vulnerability

Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 91.59% 0.997
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-693 Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

http://marc.info/?l=bugtraq&m=136439120408139&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=136733161405818&w=2
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2013/Jan/142
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2013/Jan/195
Third Party Advisory
Mailing List
http://www.kb.cert.org/vuls/id/858729
Third Party Advisory
US Government Resource
http://www.us-cert.gov/cas/techalerts/TA13-032A.html
Third Party Advisory
US Government Resource