CVE-2013-0431
MEDIUM severity · CVSS 5.3 · CWE-693 · actively exploited (CISA KEV)
5.3CVSS MEDIUM exploited ransomware
Actively exploited in the wild (CISA Known Exploited Vulnerabilities).
Known use in ransomware campaigns. Added to KEV 2022-05-25. US federal agencies must patch by 2022-06-15.
Summary
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredNone
User interactionNone
Confidentiality impactLow
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)90%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products we track (1)
Recommendation
This vulnerability is being actively exploited in the wild — patch affected products urgently. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/Advisory
- http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53
- http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.htmlAdvisory
- http://marc.info/?l=bugtraq&m=136439120408139&w=2Advisory
- http://marc.info/?l=bugtraq&m=136733161405818&w=2Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0237.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-0247.htmlAdvisory
- http://seclists.org/fulldisclosure/2013/Jan/142Advisory