VYPR
Unrated severityNVD Advisory· Published Apr 17, 2013· Updated Apr 29, 2026

CVE-2013-2422

CVE-2013-2422

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper method-invocation restrictions by the MethodUtil trampoline class, which allows remote attackers to bypass the Java sandbox.

Affected products

137
  • cpe:2.3:a:oracle:jdk:1.6.0:update22:*:*:*:*:*:*+ 31 more
    • cpe:2.3:a:oracle:jdk:1.6.0:update22:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update23:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update24:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update25:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update26:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update27:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update29:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update30:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update31:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update32:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update33:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update34:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update35:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update37:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update38:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update39:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.6.0:update41:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update1:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update10:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update11:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update13:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update15:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update2:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update3:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update4:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update5:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update6:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update7:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:1.7.0:update9:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jdk:*:update17:*:*:*:*:*:*range: <=1.7.0
    • cpe:2.3:a:oracle:jdk:*:update43:*:*:*:*:*:*range: <=1.6.0
  • cpe:2.3:a:oracle:jre:1.6.0:update22:*:*:*:*:*:*+ 31 more
    • cpe:2.3:a:oracle:jre:1.6.0:update22:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update23:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update24:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update25:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update26:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update27:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update29:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update30:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update31:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update32:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update33:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update34:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update35:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update37:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update38:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update39:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.6.0:update41:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update13:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update15:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update3:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update4:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update5:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update6:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update7:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:1.7.0:update9:*:*:*:*:*:*
    • cpe:2.3:a:oracle:jre:*:update17:*:*:*:*:*:*range: <=1.7.0
    • cpe:2.3:a:oracle:jre:*:update43:*:*:*:*:*:*range: <=1.6.0
  • Sun Corporation/Jdk21 versions
    cpe:2.3:a:sun:jdk:1.6.0:*:*:*:*:*:*:*+ 20 more
    • cpe:2.3:a:sun:jdk:1.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update1:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_10:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_11:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_12:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_13:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_14:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_15:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_16:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_17:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_18:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_19:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update1_b06:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update2:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_20:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_21:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_3:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_4:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_5:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_6:*:*:*:*:*:*
    • cpe:2.3:a:sun:jdk:1.6.0:update_7:*:*:*:*:*:*
  • Sun Corporation/Jre21 versions
    cpe:2.3:a:sun:jre:1.6.0:*:*:*:*:*:*:*+ 20 more
    • cpe:2.3:a:sun:jre:1.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_12:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_13:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_14:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_15:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_16:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_17:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_18:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_19:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_2:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_20:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_21:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_3:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_4:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_5:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_6:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_7:*:*:*:*:*:*
    • cpe:2.3:a:sun:jre:1.6.0:update_9:*:*:*:*:*:*
  • osv-coords31 versions
    < 0.53.0-r0+ 30 more
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.53.0-r0
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.48.0-r2
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 0.53.0-r1
    • (no CPE)range: < 1.7.0.121-1.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

28

News mentions

0

No linked articles in our index yet.