Junglewise Threat Intelligence

CVE-2013-0422: Oracle JRE Remote Code Execution Vulnerability

CVE-2013-0422 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-05-25

Technologies: Oracle Java Runtime Environment (JRE). Vendors: Oracle.

Executive brief

Multiple vulnerabilities in Oracle Java 7 allow remote attackers to execute arbitrary code. The flaws involve the JmxMBeanServer class's getMBeanInstantiator method and a recursive Reflection API issue that bypasses Security Manager checks due to improper frame skipping in sun.reflect.Reflection.getCallerClass.

Affected products

  • Oracle Java 7 before Update 11

Timeline

  • 2013-01-10: exploited: Exploited in the wild as a zero-day, including in Blackhole and Nuclear Pack exploit kits.
  • 2013-01-14: advisory: Oracle released a security alert for CVE-2013-0422.
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats