Executive brief
An unspecified vulnerability in the 2D component of Oracle Java SE and OpenJDK allows remote attackers to bypass the Java sandbox and affect confidentiality, integrity, and availability. The issue is reportedly related to incorrect image channel verification and can be exploited via sandboxed Java Web Start applications or applets.
Affected products
- Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier
- Oracle OpenJDK 7
Timeline
- 2013-06-18: disclosed: June 2013 Oracle Critical Patch Update (CPU)
- 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog