Executive brief
Multiple vulnerabilities in Oracle Java 7 allow remote attackers to execute arbitrary code. The flaws involve the JmxMBeanServer class's getMBeanInstantiator method and a recursive Reflection API issue that bypasses Security Manager checks due to improper frame skipping in sun.reflect.Reflection.getCallerClass.
Affected products
- Oracle Java 7 before Update 11
Timeline
- 2013-01-10: exploited: Exploited in the wild as a zero-day, including in Blackhole and Nuclear Pack exploit kits.
- 2013-01-14: advisory: Oracle released a security alert for CVE-2013-0422.
- 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.