V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2013-2460
DEB
MediumConfirmedExploit available

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows …

CVSS
6.8
Medium
EPSS
0.70
p99
Published
2013-01-01
Updated
2013-01-01
Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "insufficient access checks" in the tracing component.

Affected products
Jdk ≤ 1.7.0Jdk
CVSS vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Timeline
2013-01-01
Published
2013-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.702 · p99
Known exploited (KEV)
No
Known exploits — Сканер-ВС
26529
exploitdb · https://www.exploit-db.com/exploits/26529
Enterprise
Affected products
ProductVendorStatus
java-1.7.0-ibmTracked
java-1.7.0-ibmTracked
java-1.7.0-openjdkTracked
java-1.7.0-openjdkTracked
java-1.7.0-oracleTracked
java-1.7.0-oracleTracked
openjdk-6Tracked
openjdk-7Tracked
jdk*Tracked
jre*Tracked
Source databases
DEB
CVE
RED