CVE-2013-2423
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
A vulnerability in Java's HotSpot compiler allows attackers to bypass security restrictions and modify protected fields, potentially disabling the security manager that protects your system from malicious code.
An integrity vulnerability in Oracle JRE 7 Update 17 and OpenJDK 7 exists in the HotSpot component, exploitable via MethodHandles and reflection-based type confusion to bypass permission checks and modify public final fields, compromising the Java security manager without requiring authentication.
The full analysis of this CVE is available in Portuguese →