PT-2013-3795 · Oracle+4 · Oracle Jrockit+7
Stefan Cornelius
·
Published
2013-06-18
·
Updated
2024-06-15
·
CVE-2013-2461
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Java SE versions prior to 7 Update 21
Java SE versions prior to 6 Update 45
Oracle JRockit versions prior to R27.7.5
Oracle JRockit versions prior to R28.2.7
OpenJDK 7
Description
The issue affects confidentiality, integrity, and availability. It is related to Libraries and may allow remote attackers to bypass verification of XML signatures via vectors related to a missing check for a valid DOMCanonicalizationMethod canonicalization algorithm.
Recommendations
For Java SE versions prior to 7 Update 21, update to a version later than 7 Update 21.
For Java SE versions prior to 6 Update 45, update to a version later than 6 Update 45.
For Oracle JRockit versions prior to R27.7.5, update to a version later than R27.7.5.
For Oracle JRockit versions prior to R28.2.7, update to a version later than R28.2.7.
For OpenJDK 7, update to a version later than OpenJDK 7.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Hp-Ux
Java Platform
Java Se
Openjdk
Oracle Jrockit
Red Hat
Suse