Junglewise Threat Intelligence

CVE-2013-0431: Oracle JRE Sandbox Bypass Vulnerability

CVE-2013-0431 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2022-05-25

Technologies: Oracle Java Runtime Environment (JRE). Vendors: Oracle.

Executive brief

An unspecified vulnerability in the Java Runtime Environment (JRE) component, specifically related to JMX (Issue 52), allows remote attackers to bypass the Java security sandbox. This flaw affects Oracle Java SE 7 through Update 11 and OpenJDK 7, and has been observed being exploited in the wild.

Affected products

  • Oracle Java SE 7 through Update 11
  • OpenJDK OpenJDK 7

Timeline

  • 2013-02-01: advisory: Oracle Critical Patch Update February 2013 released.
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-05-25: disclosed

Related threats