CVE-2013-1489
Summary
| CVE | CVE-2013-1489 |
|---|---|
| State | PUBLISHED |
| Assigner | oracle |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-01-31 14:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Chrome | - | All | All | All | |
| Application | Microsoft | Internet Explorer | - | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Opera | Opera Browser | - | All | All | All |
| Application | Oracle | Jdk | 1.7.0 | update10 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update11 | All | All |
| Application | Oracle | Jre | 1.7.0 | update10 | All | All |
| Application | Oracle | Jre | 1.7.0 | update11 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: [SE-2012-01] An issue with new Java SE 7 security features | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Java update 'doesn't prevent silent exploits at all' | ZDNet | af854a3a-2127-422b-91ae-364da2661108 | www.zdnet.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| '[security bulletin] HPSBUX02857 SSRT101103 rev.1 - HP-UX Running Java, Remote Unauthorized Access, D' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Vulnerability Note VU#858729 - Oracle Java contains multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Java still unsafe, new flaws discovered - Risk - SC Magazine Australia - Secure Business Intelligence | af854a3a-2127-422b-91ae-364da2661108 | www.scmagazine.com.au | |
| Vulnerability Bypasses Oracle’s Java Applet Security Levels | af854a3a-2127-422b-91ae-364da2661108 | thenextweb.com | |
| www.informationweek.com/security/application-security/java-security-work-remains-bug-... | af854a3a-2127-422b-91ae-364da2661108 | www.informationweek.com | |
| Oracle Java Multiple Vulnerabilities | US-CERT | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| '[security bulletin] HPSBMU02874 SSRT101184 rev.1 - HP Service Manager, Java Runtime Environment (JRE' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Yet another Java security flaw discovered - Number 53 | Computerworld Blogs | af854a3a-2127-422b-91ae-364da2661108 | blogs.computerworld.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Java CPU Feb 2013 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Vendor Advisory |
| Java still unsafe, new flaws discovered - Risk - SC Magazine Australia - Secure Business Intelligence | MITRE | www.scmagazine.com.au | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.