Executive brief
Unspecified vulnerability in the HotSpot component of Oracle Java SE and OpenJDK allows remote attackers to affect integrity. The flaw reportedly enables bypassing permission checks via MethodHandles, allowing reflection and type confusion to modify public final fields and disable the security manager.
Affected products
- Oracle Java SE 7 Update 17 and earlier 7u17 and earlier
- Oracle OpenJDK 7 7
Timeline
- 2013-04-16: advisory: April 2013 Oracle Critical Patch Update (CPU) released
- 2013-04-22: patched: OpenJDK 7 patch released via IcedTea 2.3.9
- 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog