Security bypass in Oracle Java SE - CVE-2013-2423
Published: March 24, 2017 / Updated: November 20, 2020
Vulnerability identifier: #VU6171
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:A/U:Clear
CVE-ID: CVE-2013-2423
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vendor: Oracle
Affected software:
Oracle Java SE
Oracle Java SE
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The weakness caused by weak access control on static classes. Tricking the victim into running a malicious Java applet a remote attacker can bypass Java sandbox restrictions.
Successful exploitation of the vulnerability results in security bypass.
The weakness caused by weak access control on static classes. Tricking the victim into running a malicious Java applet a remote attacker can bypass Java sandbox restrictions.
Successful exploitation of the vulnerability results in security bypass.
How to mitigate CVE-2013-2423
Install update from vendor's website.