PT-2013-1345 · Oracle+2 · Java Se+4

Published

2013-04-17

·

Updated

2025-03-13

·

CVE-2013-2423

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Java SE versions prior to 7 Update 17 OpenJDK 7
Description The issue affects the integrity of the system, potentially allowing remote attackers to bypass permission checks and modify arbitrary public final fields using reflection and type confusion. This could be achieved by exploiting an unspecified vulnerability in the Java Runtime Environment component related to HotSpot. The vulnerability may also be caused by a buffer overflow in memory, which could allow a remote attacker to influence integrity or disable the security manager.
Recommendations For Java SE versions prior to 7 Update 17, update to a version later than 7 Update 17 to resolve the issue. For OpenJDK 7, consider disabling the use of the MethodHandles method and restricting reflection to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider restricting access to the HotSpot component to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03796
CESA-2013_0751
CVE-2013-2423
OPENSUSE-SU-2024:10534-1
RHSA-2013:0751
RHSA-2013:0752
RHSA-2013:0757
RHSA-2013:0822
RHSA-2013_0751
RHSA-2013_0752
RHSA-2013_0757
RHSA-2013_0822

Affected Products

Centos
Java Platform
Java Se
Openjdk
Red Hat