CVE-2013-0431
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.
In plain language
AI Act nowBusinesses using Java Runtime Environment 7 through Update 11, or OpenJDK 7, should act now because criminals have used this flaw to get around Java’s built-in safety controls.
User-assisted sandbox bypass in JRE/OpenJDK 7 related to JMX, enabling remote attackers to escape Java security restrictions through unspecified vectors.
What to do now
- Check whether any computers or servers run Java Runtime Environment 7 through Update 11 or OpenJDK 7.
- Upgrade Oracle Java SE 7 to Update 13 or later; for OpenJDK 7, install the security update supplied by your operating-system vendor.
- Remove Java 7 where it is no longer required, especially from employee computers.
- Ask IT to check for suspicious Java activity on systems that were unpatched.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:LConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2013-0431 and every CVE in our database. Create a free account — no credit card required.
Create Free Account