CVE-2013-0431
Oracle JRE Sandbox Bypass Vulnerability
CVSS
5.3
Medium
EPSS
90.0%
p100
KEV
YES
May 25, 2022
Exploit Today
80
0-100
Published: Jan 31, 2013 · Last modified: Aug 14, 2026 · CWE-693
Product
Oracle / Java Runtime Environment (JRE)
Vulnerability
Oracle JRE Sandbox Bypass Vulnerability
Added to KEV
May 25, 2022
Remediate by
Jun 15, 2022
Known ransomware use
Yes
Summary description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2013-0431
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.
- arstechnica.comhttp://arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/
- blogs.computerworld.comhttp://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53
- lists.opensuse.orghttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html
- marc.infohttp://marc.info/?l=bugtraq&m=136439120408139&w=2
- marc.infohttp://marc.info/?l=bugtraq&m=136733161405818&w=2
- rhn.redhat.comhttp://rhn.redhat.com/errata/RHSA-2013-0237.html
- rhn.redhat.comhttp://rhn.redhat.com/errata/RHSA-2013-0247.html
- seclists.orghttp://seclists.org/fulldisclosure/2013/Jan/142
- seclists.orghttp://seclists.org/fulldisclosure/2013/Jan/195
- security.gentoo.orghttp://security.gentoo.org/glsa/glsa-201406-32.xml
- www.informationweek.comhttp://www.informationweek.com/security/application-security/java-hacker-uncovers-two-flaws-in-latest/240146717
- www.kb.cert.orghttp://www.kb.cert.org/vuls/id/858729
- www.mandriva.comhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:095
- www.oracle.comhttp://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
- www.securityfocus.comhttp://www.securityfocus.com/archive/1/525387/30/0/threaded
- www.us-cert.govhttp://www.us-cert.gov/cas/techalerts/TA13-032A.html
- oval.cisecurity.orghttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16579
- oval.cisecurity.orghttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19418
- wiki.mageia.orghttps://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056
- arstechnica.comhttp://arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/