#VU6171 Security bypass in Oracle Java SE - CVE-2013-2423
Published: March 24, 2017 / Updated: November 20, 2020
Vulnerability identifier: #VU6171
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:A/U:Clear
CVE-ID: CVE-2013-2423
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerable software:
Oracle Java SE
Oracle Java SE
Software vendor:
Oracle
Oracle
Description
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The weakness caused by weak access control on static classes. Tricking the victim into running a malicious Java applet a remote attacker can bypass Java sandbox restrictions.
Successful exploitation of the vulnerability results in security bypass.
The weakness caused by weak access control on static classes. Tricking the victim into running a malicious Java applet a remote attacker can bypass Java sandbox restrictions.
Successful exploitation of the vulnerability results in security bypass.
Remediation
Install update from vendor's website.