Junglewise Threat Intelligence

CVE-2013-2465: Oracle Java SE Unspecified Vulnerability

CVE-2013-2465 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-28

Technologies: Oracle Java SE, Oracle JRockit. Vendors: Oracle.

Executive brief

An unspecified vulnerability in the 2D component of Oracle Java SE and OpenJDK allows remote attackers to bypass the Java sandbox and affect confidentiality, integrity, and availability. The issue is reportedly related to incorrect image channel verification and can be exploited via sandboxed Java Web Start applications or applets.

Affected products

  • Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier
  • Oracle OpenJDK 7

Timeline

  • 2013-06-18: disclosed: June 2013 Oracle Critical Patch Update (CPU)
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats