CVE-2013-2422
published 2013-04-17CVE-2013-2422: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier; and OpenJDK 6…
PriorityP352critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.92%
93.4th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper method-invocation restrictions by the MethodUtil trampoline class, which allows remote attackers to bypass the Java sandbox.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | <= 1.7.0 | — |
| oracle | jdk | <= 1.6.0 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | <= 1.6.0 | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2013-05-07·CVSS 10.0
CVE-2013-0401 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Ben Murphy discovered a vulnerability in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit this
to execute arbitrary code. (CVE-2013-0401)
James Forshaw discovered a vulnerability in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit this to execute arbitrary code. (CVE-2013-1488)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2013-1518, CVE-2013-1537, CVE-2013-1557, CVE-2013-1558,
CVE-2013-1569, CVE-2013-23
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2013-04-23·CVSS 10.0
CVE-2013-0401 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Ben Murphy discovered a vulnerability in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit this
to execute arbitrary code. (CVE-2013-0401)
James Forshaw discovered a vulnerability in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit this to execute arbitrary code. (CVE-2013-1488)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2013-1518, CVE-2013-1537, CVE-2013-1557, CVE-2013-1569,
CVE-2013-2383, CVE-2013-23
Red Hat
OpenJDK: MethodUtil trampoline class incorrect restrictions (Libraries, 8009857)
vendor_redhat·2013-04-16·CVSS 10.0
CVE-2013-2422 [CRITICAL] OpenJDK: MethodUtil trampoline class incorrect restrictions (Libraries, 8009857)
OpenJDK: MethodUtil trampoline class incorrect restrictions (Libraries, 8009857)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper method-invocation restrictions by the MethodUtil trampoline class, which allows remote attackers to bypass the Java sandbox.
GHSA
GHSA-vjrg-wqv9-qmc7: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier; and O
ghsa_unreviewed·2022-05-14
CVE-2013-2422 [HIGH] GHSA-vjrg-wqv9-qmc7: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier; and O
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper method-invocation restrictions by the MethodUtil trampoline class, which allows remote attackers to bypass the Java sandbox.
No detection rules found.
No public exploits indexed.
http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/http://blog.fuseyism.com/index.php/2013/04/25/security-icedtea-1-11-11-1-12-5-for-openjdk-6-released/http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/2899c3dbf5e8http://lists.apple.com/archives/security-announce/2013/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00099.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022796.htmlhttp://marc.info/?l=bugtraq&m=137283787217316&w=2http://rhn.redhat.com/errata/RHSA-2013-0752.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0757.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0758.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:145http://www.mandriva.com/security/advisories?name=MDVSA-2013:161http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.htmlhttp://www.securityfocus.com/bid/59228http://www.ubuntu.com/usn/USN-1806-1http://www.us-cert.gov/ncas/alerts/TA13-107Ahttps://bugzilla.redhat.com/show_bug.cgi?id=952642https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16561https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19087https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0124https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0130http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/http://blog.fuseyism.com/index.php/2013/04/25/security-icedtea-1-11-11-1-12-5-for-openjdk-6-released/http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/2899c3dbf5e8http://lists.apple.com/archives/security-announce/2013/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00099.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022796.htmlhttp://marc.info/?l=bugtraq&m=137283787217316&w=2http://rhn.redhat.com/errata/RHSA-2013-0752.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0757.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0758.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:145http://www.mandriva.com/security/advisories?name=MDVSA-2013:161http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.htmlhttp://www.securityfocus.com/bid/59228http://www.ubuntu.com/usn/USN-1806-1http://www.us-cert.gov/ncas/alerts/TA13-107Ahttps://bugzilla.redhat.com/show_bug.cgi?id=952642https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16561https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19087https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0124https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0130
2013-04-17
Published