cbcvebase.
CVE-2013-2469
published 2013-06-18

CVE-2013-2469: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45…

PriorityP352critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.13%
93.6th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image layout verification" in 2D.

Affected

16 ranges
VendorProductVersion rangeFixed in
oraclejdk<= 1.7.0
oraclejdk<= 1.6.0
oraclejdk<= 1.5.0
oraclejdk
oraclejdk
oraclejdk
oraclejre<= 1.7.0
oraclejre<= 1.6.0
oraclejre<= 1.5.0
oraclejre
oraclejre
oraclejre
sunjdk
sunjdk
sunjre
sunjre

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability involves incorrect image layout verification in the Java 2D component; monitor for untrusted Java applets or applications attempting to manipulate image layout data to bypass sandbox restrictions.
  • The flaw is in the 2D component's image layout verification logic (OpenJDK bug 8012601); detection should focus on Java processes invoking 2D image operations from untrusted/applet class loaders.
  • ·Affected versions are Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, and OpenJDK 7; exploitation vector and specific image layout parameters are unspecified by Oracle.
  • ·Oracle has not publicly detailed the exact attack vectors; the sandbox bypass mechanism is described only as related to 'Incorrect image layout verification' in 2D.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.