CVE-2013-1489
published 2013-01-31CVE-2013-1489: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet…
PriorityP352critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.64%
93.9th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
7: bypass of the security level setting in browser plugin (Deployment, SE-2012-01 Issue 53)
vendor_redhat·2013-01-27·CVSS 10.0
CVE-2013-1489 [CRITICAL] 7: bypass of the security level setting in browser plugin (Deployment, SE-2012-01 Issue 53)
7: bypass of the security level setting in browser plugin (Deployment, SE-2012-01 Issue 53)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability.
Package: java-1.4.2-ibm (Red Hat Enterprise Linux 5) - Will not fix
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.7.0-ibm (Red Hat Enterprise Linux 5) - Not affect
GHSA
GHSA-2684-x557-ppqj: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using I
ghsa_unreviewed·2022-05-17
CVE-2013-1489 [HIGH] GHSA-2684-x557-ppqj: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using I
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability.
No detection rules found.
No public exploits indexed.
http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53http://marc.info/?l=bugtraq&m=136439120408139&w=2http://marc.info/?l=bugtraq&m=136733161405818&w=2http://rhn.redhat.com/errata/RHSA-2013-0237.htmlhttp://seclists.org/fulldisclosure/2013/Jan/241http://thenextweb.com/insider/2013/01/28/new-vulnerability-bypasses-oracles-attempt-to-stop-malware-drive-by-downloads-via-java-applets/http://www.informationweek.com/security/application-security/java-security-work-remains-bug-hunter-sa/240147150http://www.kb.cert.org/vuls/id/858729http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.htmlhttp://www.scmagazine.com.au/News/330453%2Cjava-still-unsafe-new-flaws-discovered.aspxhttp://www.us-cert.gov/cas/techalerts/TA13-032A.htmlhttp://www.zdnet.com/java-update-doesnt-prevent-silent-exploits-at-all-7000010422/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15906https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19171http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53http://marc.info/?l=bugtraq&m=136439120408139&w=2http://marc.info/?l=bugtraq&m=136733161405818&w=2http://rhn.redhat.com/errata/RHSA-2013-0237.htmlhttp://seclists.org/fulldisclosure/2013/Jan/241http://thenextweb.com/insider/2013/01/28/new-vulnerability-bypasses-oracles-attempt-to-stop-malware-drive-by-downloads-via-java-applets/http://www.informationweek.com/security/application-security/java-security-work-remains-bug-hunter-sa/240147150http://www.kb.cert.org/vuls/id/858729http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.htmlhttp://www.scmagazine.com.au/News/330453%2Cjava-still-unsafe-new-flaws-discovered.aspxhttp://www.us-cert.gov/cas/techalerts/TA13-032A.htmlhttp://www.zdnet.com/java-update-doesnt-prevent-silent-exploits-at-all-7000010422/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15906https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19171
2013-01-31
Published