National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2013-0431 Detail

Current Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.

Source:  MITRE      Last Modified:  01/31/2013      View Analysis Description

Evaluator Description

Per: http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html "Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.)"

Quick Info

CVE Dictionary Entry:
CVE-2013-0431
Original release date:
01/31/2013
Last revised:
09/18/2017
Source:
US-CERT/NIST

Impact

CVSS Severity (version 2.0):
CVSS v2 Base Score:
5.0 MEDIUM
Vector:
(AV:N/AC:L/Au:N/C:N/I:P/A:N) (legend)
Impact Subscore:
2.9
Exploitability Subscore:
10.0
CVSS Version 2 Metrics:
Access Vector:
Network exploitable
Access Complexity:
Low
Authentication:
Not required to exploit
Impact Type:
Allows unauthorized modification

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource Type Source Name
http://arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/ External Source MISC http://arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/
http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53 External Source MISC http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html External Source SUSE openSUSE-SU-2013:0377
http://marc.info/?l=bugtraq&m=136439120408139&w=2 External Source HP HPSBUX02857
http://marc.info/?l=bugtraq&m=136733161405818&w=2 External Source HP HPSBMU02874
http://rhn.redhat.com/errata/RHSA-2013-0237.html External Source REDHAT RHSA-2013:0237
http://rhn.redhat.com/errata/RHSA-2013-0247.html External Source REDHAT RHSA-2013:0247
http://seclists.org/fulldisclosure/2013/Jan/142 External Source FULLDISC 20130118 [SE-2012-01] Java 7 Update 11 confirmed to be vulnerable
http://seclists.org/fulldisclosure/2013/Jan/195 External Source FULLDISC 20130122 Re: [SE-2012-01] Java 7 Update 11 confirmed to be vulnerable
http://security.gentoo.org/glsa/glsa-201406-32.xml External Source GENTOO GLSA-201406-32
http://www.informationweek.com/security/application-security/java-hacker-uncovers-two-flaws-in-latest/240146717 External Source MISC http://www.informationweek.com/security/application-security/java-hacker-uncovers-two-flaws-in-latest/240146717
http://www.kb.cert.org/vuls/id/858729 US Government Resource External Source CERT-VN VU#858729
http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 External Source MANDRIVA MDVSA-2013:095
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html Vendor Advisory External Source CONFIRM http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
http://www.securityfocus.com/archive/1/525387/30/0/threaded External Source BUGTRAQ 20130122 Re: [SE-2012-01] Java 7 Update 11 confirmed to be vulnerable
http://www.us-cert.gov/cas/techalerts/TA13-032A.html US Government Resource External Source CERT TA13-032A
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16579 External Source OVAL oval:org.mitre.oval:def:16579
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19418 External Source OVAL oval:org.mitre.oval:def:19418
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056 External Source CONFIRM https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056

Technical Details

Vulnerability Type (View All)

Change History 2 change records found - show changes