⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2022-06-15.

CVE-2013-0431Protection Mechanism Failure in Oracle JRE

Severity
5.3MEDIUMNVD
EPSS
91.6%
top 0.32%
CISA KEV
KEVRansomware
Added 2022-05-25
Due 2022-06-15
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedJan 31
KEV addedMay 25
KEV dueJun 15
CISA Required Action: Apply updates per vendor instructions.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDoracle/jre1.7.0

🔴Vulnerability Details

3
GHSA
GHSA-h3cw-j9j9-5pc4: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted r2022-05-05
CVEList
CVE-2013-0431: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted r2013-01-31
VulnCheck
Oracle JRE Sandbox Bypass Vulnerability2013

💥Exploits & PoCs

1
Exploit-DB
Java Applet JMX - Remote Code Execution (Metasploit) (2)2013-02-25

📋Vendor Advisories

5
CISA
Oracle JRE Sandbox Bypass Vulnerability2022-05-25
Red Hat
mysql: unspecified DoS related to InnoDB subcomponent (CPU Jan 2014)2014-01-14
Red Hat
mysql: unspecified vulnerability related to InnoDB DoS (CPU Jan 2014)2014-01-14
Red Hat
OpenJDK: JMX Introspector missing package access check (JMX, 8000539, SE-2012-01 Issue 52)2013-01-27
Red Hat
JDK: complete Java security sandbox bypass (Issue 51)2013-01-27

💬Community

3
Bugzilla
CVE-2014-0431 mysql: unspecified vulnerability related to InnoDB DoS (CPU Jan 2014)2014-01-15
Bugzilla
CVE-2013-1490 JDK: complete Java security sandbox bypass (Issue 51)2013-01-31
Bugzilla
CVE-2013-0431 OpenJDK: JMX Introspector missing package access check (JMX, 8000539, SE-2012-01 Issue 52)2013-01-31
CVE-2013-0431 — Protection Mechanism Failure in Oracle | cvebase