CVE-2013-2423

CVSS 2.0 Score 4.3 of 10 (medium)

Details

Published Apr 17, 2013
Updated: Dec 20, 2024

Summary

CVE-2013-2423 is a vulnerability affecting the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, as well as OpenJDK 7. This issue, which was discovered but not yet confirmed by Oracle, may allow remote attackers to manipulate the integrity of the system through unknown vectors related to the HotSpot component. Initial reports suggest that this vulnerability could enable attackers to bypass permission checks using the MethodHandles method and modify arbitrary public final fields via reflection and type confusion, potentially disabling the security manager. However, Oracle has not yet verified these claims.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Java Runtime Environment
  • Open SUSE
  • Ubuntu Linux

Affected Vendors

  • Opensuse
  • Canonical System