5.3

CVE-2013-0431

Warnung

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OracleJre Version1.7.0 Update-
OracleJre Version1.7.0 Updateupdate1
OracleJre Version1.7.0 Updateupdate10
OracleJre Version1.7.0 Updateupdate11
OracleJre Version1.7.0 Updateupdate2
OracleJre Version1.7.0 Updateupdate3
OracleJre Version1.7.0 Updateupdate4
OracleJre Version1.7.0 Updateupdate5
OracleJre Version1.7.0 Updateupdate6
OracleJre Version1.7.0 Updateupdate7
OracleJre Version1.7.0 Updateupdate9
OracleOpenjdk Version7 Update-

25.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Oracle JRE Sandbox Bypass Vulnerability

Schwachstelle

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 91.59% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-693 Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

http://marc.info/?l=bugtraq&m=136439120408139&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=136733161405818&w=2
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2013/Jan/142
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2013/Jan/195
Third Party Advisory
Mailing List
http://www.kb.cert.org/vuls/id/858729
Third Party Advisory
US Government Resource
http://www.us-cert.gov/cas/techalerts/TA13-032A.html
Third Party Advisory
US Government Resource