PT-2013-1345 · Oracle+2 · Java Se+4
Published
2013-04-17
·
Updated
2025-03-13
·
CVE-2013-2423
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Java SE versions prior to 7 Update 17
OpenJDK 7
Description
The issue affects the integrity of the system, potentially allowing remote attackers to bypass permission checks and modify arbitrary public final fields using reflection and type confusion. This could be achieved by exploiting an unspecified vulnerability in the Java Runtime Environment component related to HotSpot. The vulnerability may also be caused by a buffer overflow in memory, which could allow a remote attacker to influence integrity or disable the security manager.
Recommendations
For Java SE versions prior to 7 Update 17, update to a version later than 7 Update 17 to resolve the issue.
For OpenJDK 7, consider disabling the use of the MethodHandles method and restricting reflection to minimize the risk of exploitation until a patch is available.
As a temporary workaround, consider restricting access to the HotSpot component to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Java Platform
Java Se
Openjdk
Red Hat