Junglewise Threat Intelligence

CVE-2013-2423: Oracle JRE Unspecified Vulnerability

CVE-2013-2423 · Severity: critical · CVSS 4.3 · Exploited in the wild · Published 2022-05-25

Technologies: Oracle Java Runtime Environment (JRE). Vendors: Oracle.

Executive brief

Unspecified vulnerability in the HotSpot component of Oracle Java SE and OpenJDK allows remote attackers to affect integrity. The flaw reportedly enables bypassing permission checks via MethodHandles, allowing reflection and type confusion to modify public final fields and disable the security manager.

Affected products

  • Oracle Java SE 7 Update 17 and earlier 7u17 and earlier
  • Oracle OpenJDK 7 7

Timeline

  • 2013-04-16: advisory: April 2013 Oracle Critical Patch Update (CPU) released
  • 2013-04-22: patched: OpenJDK 7 patch released via IcedTea 2.3.9
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats