Medium severity5.3CISA KEVNVD Advisory· Published Jan 31, 2013· Updated Apr 21, 2026
CVE-2013-0431
CVE-2013-0431
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.
Affected products
12cpe:2.3:a:oracle:jre:1.7.0:-:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:oracle:jre:1.7.0:-:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.7.0:update3:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.7.0:update4:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.7.0:update5:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.7.0:update6:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.7.0:update7:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:1.7.0:update9:*:*:*:*:*:*
- cpe:2.3:a:oracle:openjdk:7:-:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
20- arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.htmlnvdThird Party Advisory
- marc.infonvdMailing ListThird Party Advisory
- marc.infonvdMailing ListThird Party Advisory
- rhn.redhat.com/errata/RHSA-2013-0237.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2013-0247.htmlnvdThird Party Advisory
- seclists.org/fulldisclosure/2013/Jan/142nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2013/Jan/195nvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/glsa-201406-32.xmlnvdThird Party Advisory
- www.kb.cert.org/vuls/id/858729nvdThird Party AdvisoryUS Government Resource
- www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.htmlnvdVendor Advisory
- www.securityfocus.com/archive/1/525387/30/0/threadednvdThird Party AdvisoryVDB Entry
- www.us-cert.gov/cas/techalerts/TA13-032A.htmlnvdThird Party AdvisoryUS Government Resource
- wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056nvdThird Party Advisory
- blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53nvdNot Applicable
- www.informationweek.com/security/application-security/java-hacker-uncovers-two-flaws-in-latest/240146717nvdBroken Link
- www.mandriva.com/security/advisoriesnvdNot Applicable
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16579nvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19418nvdBroken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.