Security bypass in Oracle Java SE - CVE-2013-2423
Published: March 24, 2017 / Updated: November 20, 2020
Vulnerability identifier: #VU6171
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-2423
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The weakness caused by weak access control on static classes. Tricking the victim into running a malicious Java applet a remote attacker can bypass Java sandbox restrictions.
Successful exploitation of the vulnerability results in security bypass.
The weakness caused by weak access control on static classes. Tricking the victim into running a malicious Java applet a remote attacker can bypass Java sandbox restrictions.
Successful exploitation of the vulnerability results in security bypass.
Affected software
Oracle Java SE
How to mitigate CVE-2013-2423
Install update from vendor's website.