cbcvebase.
CVE-2013-2463
published 2013-06-18

CVE-2013-2463: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45…

PriorityP352critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
10.18%
95.2th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image attribute verification" in 2D.

Affected

16 ranges
VendorProductVersion rangeFixed in
oraclejdk<= 1.7.0
oraclejdk<= 1.6.0
oraclejdk<= 1.5.0
oraclejdk
oraclejdk
oraclejdk
oraclejre<= 1.7.0
oraclejre<= 1.6.0
oraclejre<= 1.5.0
oraclejre
oraclejre
oraclejre
sunjdk
sunjdk
sunjre
sunjre

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability allows bypassing the Java sandbox via incorrect image attribute verification in the 2D component; detect untrusted Java applets or applications attempting to manipulate image attributes to escape sandbox restrictions.
  • The flaw is in the 2D component's image attribute verification logic (OpenJDK bug 8012438); monitor for exploitation attempts targeting Java 2D image processing in JRE versions 7u21 and earlier, 6u45 and earlier, and 5.0u45 and earlier.
  • The upstream fix commit for OpenJDK7 can be used as a reference to identify the exact code change and build detection logic around the vulnerable code path.
  • ·The attack vectors are unspecified by Oracle; exploitation details are not publicly documented beyond the 2D image attribute verification bypass mechanism.
  • ·Oracle has not confirmed the sandbox bypass vector; the claim originates from a third-party vendor.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.