CVE-2013-2423Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.
CWE-284 · Improper access control
Exploited in the wild
Confirmed real-world exploitation.
CVSS E:A
| Index | Artifact | Stars | First seen |
|---|---|---|---|
| Exploit-DB | Java Applet - Reflection Type Confusion Remote Code Execution (Metasploit) | 2013-04-23 |
A defect of the type ARMR addresses, with a fix path to work from and a working exploit already published. This is a claim on attention, not a scheduling commitment: no rule exists and none is scheduled.
| Decided by | manual classification : Manual classification of this CVE in the legacy dataset |
|---|---|
| Finding | Manual classification assigned status: MITIGATION-CANDIDATE |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
2 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
CISA-ADP | Secondary | published |
| CVSS 2.0 | 4.3 | no band published | AV:N/AC:M/Au:N/C:N/I:P/A:N |
NVD | Primary |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Java SE CPU Apr 2013 ↗ | CPU | 2013-Q2 | Oracle Java SE / Java Runtime Environment (7 Update 17 and before) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Java SE | Java Runtime Environment | 7 Update 17 and before |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | canonical | ubuntu linux | generic | 12.10 |
| nvd | opensuse | opensuse | generic | 12.3 |
| nvd | oracle | jre | javase | 1.7.0 · 1.7.0:update1 · 1.7.0:update2 · 1.7.0:update3 · 1.7.0:update4 · 1.7.0:update5 · 1.7.0:update6 · 1.7.0:update7 · 1.7.0:update9 · 1.7.0:update10 · 1.7.0:update11 · 1.7.0:update13 · 1.7.0:update15 |
A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.
## Manual Classification Context **Labels:** HOSTSPOT, HOTSPOT, MULTIPLE, SEE NOTE 1, NO AUTH REMOTE EXPLOIT **Products:** OPENJDK, JAVA RUNTIME ENVIRONMENT, ORACLE JAVA SE
| URL | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2013:0751 | ADVISORY, RHSA-2013:0751 |
| https://access.redhat.com/security/cve/CVE-2013-2423 | REPORT, RHSA-2013:0751 |
| https://access.redhat.com/errata/RHSA-2013:0752 | ADVISORY, RHSA-2013:0752 |
| http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/ | Broken Link |
| http://blog.spiderlabs.com/2013/04/java-is-so-confusing.html | Not Applicable |
| http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/b453d9be6b3f | Patch |
| http://lists.opensuse.org/opensuse-updates/2013-06/msg00099.html | Third Party Advisory |
| http://rhn.redhat.com/errata/RHSA-2013-0752.html | Third Party Advisory |
| http://rhn.redhat.com/errata/RHSA-2013-0757.html | Third Party Advisory |
| http://security.gentoo.org/glsa/glsa-201406-32.xml | Third Party Advisory |
| Published | 2013-04-17 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-16 | NVD's own last-modified date for this record. |