Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 90.0%; technical severity is CVSS 5.3.
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.
Who should care
- Teams operating Java Runtime Environment (JRE), Jre, Openjdk
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Java Runtime Environment (JRE), Jre, Openjdk is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Oracle Security advisory Javacpufeb2013 1841061
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Advisory
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- CWE
- CWE-693
- Affected versions
- Oracle Java Runtime Environment (JRE); Oracle Jre (Version 1.7.0 | Version 1.7.0 | Version 1.7.0 | Version 1.7.0); Oracle Openjdk (Version 7)
- Fixed versions
- No explicit fixed version is currently recorded.
- Published
- 31 January 2013
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 90.0%
- Signal calculated at 82
External references
- Red Hat Third-party advisory RHSA 2013 0237
- Red Hat Third-party advisory RHSA 2013 0247
- CERT/CC Government advisory 858729
- CISA Government advisory CVE-2013-0431
- Arstechnica Third-party advisory Critical Java Vulnerabilies Confirmed In Latest Version
- Lists Opensuse Third-party advisory Msg00001
- Marc Info Third-party advisory
- Marc Info Third-party advisory
- Seclists Third-party advisory
- Seclists Third-party advisory
- Informationweek Technical reference 240146717
- Mandriva Technical reference