[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-0444Date: (C)2013-02-02   (M)2023-12-22


Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient checks for cached results" by the Java Beans MethodFinder, which might allow attackers to access methods that should only be accessible to privileged code.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.6
Exploit Score: 4.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
GLSA-201406-32
HPSBMU02874
HPSBUX02857
MDVSA-2013:095
RHSA-2013:0237
RHSA-2013:0247
TA13-032A
VU#858729
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907218
http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce04db4aba39
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056
openSUSE-SU-2013:0377
oval:org.mitre.oval:def:16614
oval:org.mitre.oval:def:19349

CPE    22
cpe:/a:oracle:jre:1.7.0:update11
cpe:/a:oracle:jdk:1.7.0
cpe:/a:oracle:jre:1.7.0:update10
cpe:/a:oracle:jre:1.7.0
...
OVAL    10
oval:org.secpod.oval:def:701171
oval:org.secpod.oval:def:9155
oval:org.secpod.oval:def:505509
oval:org.secpod.oval:def:505594
...

© SecPod Technologies