{"api_version":"1","generated_at":"2026-07-24T01:39:24+00:00","cve":"CVE-2013-1489","urls":{"html":"https://cve.report/CVE-2013-1489","api":"https://cve.report/api/cve/CVE-2013-1489.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-1489","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-1489"},"summary":{"title":"CVE-2013-1489","description":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the \"Very High\" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka \"Issue 53\" and the \"Java Security Slider\" vulnerability.","state":"PUBLISHED","assigner":"oracle","published_at":"2013-01-31 14:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://seclists.org/fulldisclosure/2013/Jan/241","name":"http://seclists.org/fulldisclosure/2013/Jan/241","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Full Disclosure: [SE-2012-01] An issue with new Java SE 7 security\tfeatures","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15906","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15906","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zdnet.com/java-update-doesnt-prevent-silent-exploits-at-all-7000010422/","name":"http://www.zdnet.com/java-update-doesnt-prevent-silent-exploits-at-all-7000010422/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Java update 'doesn't prevent silent exploits at all' | ZDNet","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2013-0237.html","name":"http://rhn.redhat.com/errata/RHSA-2013-0237.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=136439120408139&w=2","name":"http://marc.info/?l=bugtraq&m=136439120408139&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[security bulletin] HPSBUX02857 SSRT101103 rev.1 - HP-UX Running Java, Remote Unauthorized Access, D' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.kb.cert.org/vuls/id/858729","name":"http://www.kb.cert.org/vuls/id/858729","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"Vulnerability Note VU#858729 - Oracle Java contains multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.scmagazine.com.au/News/330453%2Cjava-still-unsafe-new-flaws-discovered.aspx","name":"http://www.scmagazine.com.au/News/330453%2Cjava-still-unsafe-new-flaws-discovered.aspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Java still unsafe, new flaws discovered - Risk - SC Magazine Australia - Secure Business Intelligence","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://thenextweb.com/insider/2013/01/28/new-vulnerability-bypasses-oracles-attempt-to-stop-malware-drive-by-downloads-via-java-applets/","name":"http://thenextweb.com/insider/2013/01/28/new-vulnerability-bypasses-oracles-attempt-to-stop-malware-drive-by-downloads-via-java-applets/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Vulnerability Bypasses Oracle’s Java Applet Security Levels","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.informationweek.com/security/application-security/java-security-work-remains-bug-hunter-sa/240147150","name":"http://www.informationweek.com/security/application-security/java-security-work-remains-bug-hunter-sa/240147150","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA13-032A.html","name":"http://www.us-cert.gov/cas/techalerts/TA13-032A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"Oracle Java Multiple Vulnerabilities | US-CERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=136733161405818&w=2","name":"http://marc.info/?l=bugtraq&m=136733161405818&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[security bulletin] HPSBMU02874 SSRT101184 rev.1 - HP Service Manager, Java Runtime Environment (JRE' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53","name":"http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Yet another Java security flaw discovered - Number 53  | Computerworld Blogs","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19171","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19171","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","name":"http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Java CPU Feb 2013","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.scmagazine.com.au/News/330453,java-still-unsafe-new-flaws-discovered.aspx","name":"MISC:http://www.scmagazine.com.au/News/330453,java-still-unsafe-new-flaws-discovered.aspx","refsource":"MITRE","tags":[],"title":"Java still unsafe, new flaws discovered - Risk - SC Magazine Australia - Secure Business Intelligence","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-1489","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-1489","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"1489","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"google","cpe5":"chrome","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1489","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1489","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1489","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opera","cpe5":"opera_browser","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1489","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"jdk","cpe6":"1.7.0","cpe7":"update10","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1489","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"jdk","cpe6":"1.7.0","cpe7":"update11","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1489","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"jre","cpe6":"1.7.0","cpe7":"update10","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"1489","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"jre","cpe6":"1.7.0","cpe7":"update11","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T15:04:48.915Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"oval:org.mitre.oval:def:15906","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15906"},{"name":"20130127 [SE-2012-01] An issue with new Java SE 7 security features","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2013/Jan/241"},{"name":"TA13-032A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA13-032A.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zdnet.com/java-update-doesnt-prevent-silent-exploits-at-all-7000010422/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://thenextweb.com/insider/2013/01/28/new-vulnerability-bypasses-oracles-attempt-to-stop-malware-drive-by-downloads-via-java-applets/"},{"name":"VU#858729","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/858729"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.scmagazine.com.au/News/330453%2Cjava-still-unsafe-new-flaws-discovered.aspx"},{"name":"RHSA-2013:0237","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0237.html"},{"name":"HPSBUX02857","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=136439120408139&w=2"},{"name":"HPSBMU02874","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=136733161405818&w=2"},{"name":"SSRT101103","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=136439120408139&w=2"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.informationweek.com/security/application-security/java-security-work-remains-bug-hunter-sa/240147150"},{"name":"SSRT101184","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=136733161405818&w=2"},{"name":"oval:org.mitre.oval:def:19171","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19171"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-01-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the \"Very High\" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka \"Issue 53\" and the \"Java Security Slider\" vulnerability."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"43595867-4340-4103-b7a2-9a5208d29a85","shortName":"oracle"},"references":[{"name":"oval:org.mitre.oval:def:15906","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15906"},{"name":"20130127 [SE-2012-01] An issue with new Java SE 7 security features","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2013/Jan/241"},{"name":"TA13-032A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA13-032A.html"},{"tags":["x_refsource_MISC"],"url":"http://www.zdnet.com/java-update-doesnt-prevent-silent-exploits-at-all-7000010422/"},{"tags":["x_refsource_MISC"],"url":"http://thenextweb.com/insider/2013/01/28/new-vulnerability-bypasses-oracles-attempt-to-stop-malware-drive-by-downloads-via-java-applets/"},{"name":"VU#858729","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/858729"},{"tags":["x_refsource_MISC"],"url":"http://www.scmagazine.com.au/News/330453%2Cjava-still-unsafe-new-flaws-discovered.aspx"},{"name":"RHSA-2013:0237","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0237.html"},{"name":"HPSBUX02857","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=136439120408139&w=2"},{"name":"HPSBMU02874","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=136733161405818&w=2"},{"name":"SSRT101103","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=136439120408139&w=2"},{"tags":["x_refsource_MISC"],"url":"http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html"},{"tags":["x_refsource_MISC"],"url":"http://www.informationweek.com/security/application-security/java-security-work-remains-bug-hunter-sa/240147150"},{"name":"SSRT101184","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=136733161405818&w=2"},{"name":"oval:org.mitre.oval:def:19171","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19171"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert_us@oracle.com","ID":"CVE-2013-1489","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the \"Very High\" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka \"Issue 53\" and the \"Java Security Slider\" vulnerability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"oval:org.mitre.oval:def:15906","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15906"},{"name":"20130127 [SE-2012-01] An issue with new Java SE 7 security features","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2013/Jan/241"},{"name":"TA13-032A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA13-032A.html"},{"name":"http://www.zdnet.com/java-update-doesnt-prevent-silent-exploits-at-all-7000010422/","refsource":"MISC","url":"http://www.zdnet.com/java-update-doesnt-prevent-silent-exploits-at-all-7000010422/"},{"name":"http://thenextweb.com/insider/2013/01/28/new-vulnerability-bypasses-oracles-attempt-to-stop-malware-drive-by-downloads-via-java-applets/","refsource":"MISC","url":"http://thenextweb.com/insider/2013/01/28/new-vulnerability-bypasses-oracles-attempt-to-stop-malware-drive-by-downloads-via-java-applets/"},{"name":"VU#858729","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/858729"},{"name":"http://www.scmagazine.com.au/News/330453,java-still-unsafe-new-flaws-discovered.aspx","refsource":"MISC","url":"http://www.scmagazine.com.au/News/330453,java-still-unsafe-new-flaws-discovered.aspx"},{"name":"RHSA-2013:0237","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2013-0237.html"},{"name":"HPSBUX02857","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=136439120408139&w=2"},{"name":"HPSBMU02874","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=136733161405818&w=2"},{"name":"SSRT101103","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=136439120408139&w=2"},{"name":"http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53","refsource":"MISC","url":"http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53"},{"name":"http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html"},{"name":"http://www.informationweek.com/security/application-security/java-security-work-remains-bug-hunter-sa/240147150","refsource":"MISC","url":"http://www.informationweek.com/security/application-security/java-security-work-remains-bug-hunter-sa/240147150"},{"name":"SSRT101184","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=136733161405818&w=2"},{"name":"oval:org.mitre.oval:def:19171","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19171"}]}}}},"cveMetadata":{"assignerOrgId":"43595867-4340-4103-b7a2-9a5208d29a85","assignerShortName":"oracle","cveId":"CVE-2013-1489","datePublished":"2013-01-31T14:10:00.000Z","dateReserved":"2013-01-30T00:00:00.000Z","dateUpdated":"2024-08-06T15:04:48.915Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2013-01-31 14:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:1.7.0:update10:*:*:*:windows:*:*","matchCriteriaId":"1C74FCFD-B3D1-48D5-9CD0-99DE675B8643"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:1.7.0:update11:*:*:*:windows:*:*","matchCriteriaId":"88BF7EF1-A70B-4BA3-A564-9E14ECFD098A"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:windows:*:*","matchCriteriaId":"70E771E8-F2A9-4A8D-BD7A-B2D69828675B"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:windows:*:*","matchCriteriaId":"9752AB75-1457-4A6A-A310-29410A0905C2"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:*","matchCriteriaId":"39B565E1-C2F1-44FC-A517-E3130332B17C"},{"vulnerable":false,"criteria":"cpe:2.3:a:microsoft:internet_explorer:-:*:*:*:*:*:*:*","matchCriteriaId":"C37BA825-679F-4257-9F2B-CE2318B75396"},{"vulnerable":false,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","matchCriteriaId":"14E6A30E-7577-4569-9309-53A0AF7FE3AC"},{"vulnerable":false,"criteria":"cpe:2.3:a:opera:opera_browser:-:*:*:*:*:*:*:*","matchCriteriaId":"4545786D-3129-4D92-B218-F4A92428ED48"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"1489","Ordinal":"1","Title":"CVE-2013-1489","CVE":"CVE-2013-1489","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"1489","Ordinal":"1","NoteData":"Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the \"Very High\" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka \"Issue 53\" and the \"Java Security Slider\" vulnerability.","Type":"Description","Title":"CVE-2013-1489"},{"CveYear":"2013","CveId":"1489","Ordinal":"2","NoteData":"2013-01-31","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"1489","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}