CVE-2013-2461Oracle Jrockit vulnerability

8 documents7 sources
Severity
7.5HIGHNVD
EPSS
70.9%
top 1.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 18
Latest updateMay 14

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the Oracle JRockit component in Oracle Fusion Middleware R27.7.5 and earlier and R28.2.7 and earlier; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the June and July 2013 CPU. Oracle has not commented on claims from another ven

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages5 packages

NVDoracle/jrockitr27.7.1r27.7.5+1
NVDoracle/openjdk1.7.0
NVDoracle/jdk1.6.0
NVDoracle/jre1.7.0
NVDsun/jdk1.6.0

🔴Vulnerability Details

3
GHSA
GHSA-xp47-mpxp-9h7v: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the O2022-05-14
CVEList
CVE-2013-2461: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the O2013-06-18
VulnCheck
Oracle Java Runtime Environment (JRE), JRockit, Fusion Middleware, and OpenJDK 7 Unspecified Libraries Vulnerability2013

📋Vendor Advisories

3
Ubuntu
OpenJDK 6 vulnerabilities2013-07-23
Ubuntu
OpenJDK 7 vulnerabilities2013-07-16
Red Hat
OpenJDK: Missing check for valid DOMCanonicalizationMethod canonicalization algorithm (Libraries, 8014281)2013-06-18

💬Community

1
Bugzilla
CVE-2013-2461 OpenJDK: Missing check for valid DOMCanonicalizationMethod canonicalization algorithm (Libraries, 8014281)2013-06-17
CVE-2013-2461 — Oracle Jrockit vulnerability | cvebase