CVE-2013-5887
published 2014-01-15CVE-2013-5887: Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect availability via unknown vectors related to Deployment.
PriorityP427medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.17%
89.9th percentile
Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect availability via unknown vectors related to Deployment.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
vendor_redhat·2014-01-14·CVSS 5.0
CVE-2013-5887 [MEDIUM] JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect availability via unknown vectors related to Deployment.
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 7) - Not affected
Red Hat
tomcat: DIGEST authentication vulnerable to replay attacks
vendor_redhat·2013-05-28·CVSS 5.0
CVE-2013-2051 [MEDIUM] tomcat: DIGEST authentication vulnerable to replay attacks
tomcat: DIGEST authentication vulnerable to replay attacks
The Tomcat 6 DIGEST authentication functionality as used in Red Hat Enterprise Linux 6 allows remote attackers to bypass intended access restrictions by performing a replay attack after a nonce becomes stale. NOTE: this issue is due to an incomplete fix for CVE-2012-5887.
GHSA
GHSA-hcc6-h77r-jqhr: Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect availability via unknown vectors related to Deployment
ghsa_unreviewed·2022-05-13
CVE-2013-5887 [MEDIUM] GHSA-hcc6-h77r-jqhr: Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect availability via unknown vectors related to Deployment
Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect availability via unknown vectors related to Deployment.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5887 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
bugzilla·2014-01-15·CVSS 5.0
CVE-2013-5887 [MEDIUM] CVE-2013-5887 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
CVE-2013-5887 Oracle JDK: unspecified vulnerability fixed in 6u71 and 7u51 (Deployment)
Oracle Java SE 6u71 and 7u51 fixes an unspecified vulnerability in the Deployment component (CVE-2013-5887). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2014:0030 https://rhn.redhat.com/errata/RHSA-2014-0030.html
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2014:0135 https://rhn.redhat.com
Bugzilla
CVE-2013-2051 tomcat: DIGEST authentication vulnerable to replay attacks
bugzilla·2013-05-03·CVSS 5.0
CVE-2013-2051 [MEDIUM] CVE-2013-2051 tomcat: DIGEST authentication vulnerable to replay attacks
CVE-2013-2051 tomcat: DIGEST authentication vulnerable to replay attacks
It was found that the fix for CVE-2012-5887 shipped for tomcat 6 on Red Hat Enterprise Linux 6 (RHSA-2013:0623) was incomplete. The fix only allowed DIGEST authentication to succeed when a stale nonce was provided, rather than when a stale nonce was NOT provided. As a result, DIGEST authentication did not function. However, a man-in-the-middle attacker could record a DIGEST authentication exchange, wait until the associated nonce is marked as stale on the server, then successfully replay this request.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0869 https://rhn.redhat.com/errata/RHSA-2013-0869.html
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00024.htmlhttp://marc.info/?l=bugtraq&m=139402697611681&w=2http://marc.info/?l=bugtraq&m=139402749111889&w=2http://osvdb.org/102013http://rhn.redhat.com/errata/RHSA-2014-0030.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0134.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0135.htmlhttp://secunia.com/advisories/56485http://secunia.com/advisories/56535http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.securityfocus.com/bid/64758http://www.securityfocus.com/bid/64875http://www.securitytracker.com/id/1029608https://access.redhat.com/errata/RHSA-2014:0414https://exchange.xforce.ibmcloud.com/vulnerabilities/90345https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00024.htmlhttp://marc.info/?l=bugtraq&m=139402697611681&w=2http://marc.info/?l=bugtraq&m=139402749111889&w=2http://osvdb.org/102013http://rhn.redhat.com/errata/RHSA-2014-0030.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0134.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0135.htmlhttp://secunia.com/advisories/56485http://secunia.com/advisories/56535http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.securityfocus.com/bid/64758http://www.securityfocus.com/bid/64875http://www.securitytracker.com/id/1029608https://access.redhat.com/errata/RHSA-2014:0414https://exchange.xforce.ibmcloud.com/vulnerabilities/90345https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777
2014-01-15
Published