CVE-2013-2423lowunder attackCWE-284

CVE-2013-2423

Published · Updated

95Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 3.7epss 85%
from disclosure to weapon6 days
Published on NVDApr 17
1st PoC+6d
metasploitJan 10
CISA KEV+3325d
exploitation probability
85%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
14 products (202 components)
Red Hat Enterprise Linux Server Supplementary (v. 5) · Red Hat Enterprise Linux Server Supplementary (v. 6) · Red Hat Enterprise Linux Desktop Supplementary (v. 6) · Red Hat Enterprise Linux Workstation Supplementary (v. 6) · Red Hat Enterprise Linux (v. 5 server) · and others 9
Not affected
2 products (20 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 5
Action required by CISAfederal deadline: 2022-06-15

Apply updates per vendor instructions.

In short

A vulnerability in Java's HotSpot compiler allows attackers to bypass security restrictions and modify protected fields, potentially disabling the security manager that protects your system from malicious code.

Technical detail

An integrity vulnerability in Oracle JRE 7 Update 17 and OpenJDK 7 exists in the HotSpot component, exploitable via MethodHandles and reflection-based type confusion to bypass permission checks and modify public final fields, compromising the Java security manager without requiring authentication.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.