{"api_version":"1","generated_at":"2026-07-23T11:09:16+00:00","cve":"CVE-2013-5893","urls":{"html":"https://cve.report/CVE-2013-5893","api":"https://cve.report/api/cve/CVE-2013-5893.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-5893","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-5893"},"summary":{"title":"CVE-2013-5893","description":"Unspecified vulnerability in Oracle Java SE 7u45 and Java SE Embedded 7u45, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to improper handling of methods in MethodHandles in HotSpot JVM, which allows attackers to escape the sandbox.","state":"PUBLISHED","assigner":"oracle","published_at":"2014-01-15 16:08:06","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","name":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Oracle Critical Patch Update - January 2014","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://hg.openjdk.java.net/jdk7u/jdk7u/hotspot/rev/839100e42498","name":"http://hg.openjdk.java.net/jdk7u/jdk7u/hotspot/rev/839100e42498","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"jdk7u/jdk7u/hotspot: 839100e42498","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-0030.html","name":"http://rhn.redhat.com/errata/RHSA-2014-0030.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/56486","name":"http://secunia.com/advisories/56486","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA56486 - Oracle Java SE Embedded Multiple Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=139402697611681&w=2","name":"http://marc.info/?l=bugtraq&m=139402697611681&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[security bulletin] HPSBUX02972 SSRT101454 rev.1 - HP-UX Running Java7, Remote Unauthorized Access, ' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/56485","name":"http://secunia.com/advisories/56485","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-0026.html","name":"http://rhn.redhat.com/errata/RHSA-2014-0026.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/56535","name":"http://secunia.com/advisories/56535","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA56535 - Red Hat update for java-1.7.0-oracle - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777","name":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Document Display | HPE Support Center","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-0027.html","name":"http://rhn.redhat.com/errata/RHSA-2014-0027.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://osvdb.org/102000","name":"http://osvdb.org/102000","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1029608","name":"http://www.securitytracker.com/id/1029608","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Java Multiple Flaws Let Remote Users Execute Arbitrary Code, Access and Modify Data, and Deny Service - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2014-02/msg00000.html","name":"http://lists.opensuse.org/opensuse-updates/2014-02/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"openSUSE-SU-2014:0180-1: moderate: update for java-1_7_0-openjdk","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://secunia.com/advisories/56432","name":"http://secunia.com/advisories/56432","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA56432 - Red Hat update for java-1.7.0-openjdk - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/64758","name":"http://www.securityfocus.com/bid/64758","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RETIRED: Oracle January 2014 Critical Patch Update Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1051549","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1051549","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 1051549 – CVE-2013-5893 OpenJDK: JVM method processing issues (Libraries, 8029507)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00105.html","name":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00105.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"openSUSE-SU-2014:0174-1: moderate: update for java-1_7_0-openjdk","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00107.html","name":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00107.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"openSUSE-SU-2014:0177-1: moderate: update for java-1_7_0-openjdk","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.ubuntu.com/usn/USN-2089-1","name":"http://www.ubuntu.com/usn/USN-2089-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-2089-1: OpenJDK 7 vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/64863","name":"http://www.securityfocus.com/bid/64863","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Java SE CVE-2013-5893 Remote Security Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-5893","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-5893","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"5893","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"jdk","cpe6":"1.7.0","cpe7":"update45","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"5893","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"jre","cpe6":"1.7.0","cpe7":"update45","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2013","cve_id":"5893","cve":"CVE-2013-5893","epss":"0.069800000","percentile":"0.914820000","score_date":"2026-05-01","updated_at":"2026-05-02 00:02:52"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T17:22:31.300Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"56432","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/56432"},{"name":"openSUSE-SU-2014:0174","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00105.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://hg.openjdk.java.net/jdk7u/jdk7u/hotspot/rev/839100e42498"},{"name":"56535","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/56535"},{"name":"USN-2089-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2089-1"},{"name":"102000","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/102000"},{"name":"RHSA-2014:0030","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0030.html"},{"name":"56485","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/56485"},{"name":"SSRT101454","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139402697611681&w=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777"},{"name":"HPSBUX02972","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139402697611681&w=2"},{"name":"RHSA-2014:0027","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0027.html"},{"name":"56486","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/56486"},{"name":"1029608","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1029608"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1051549"},{"name":"64863","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/64863"},{"name":"RHSA-2014:0026","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0026.html"},{"name":"64758","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/64758"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html"},{"name":"openSUSE-SU-2014:0180","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2014-02/msg00000.html"},{"name":"openSUSE-SU-2014:0177","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00107.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-01-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in Oracle Java SE 7u45 and Java SE Embedded 7u45, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to improper handling of methods in MethodHandles in HotSpot JVM, which allows attackers to escape the sandbox."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-09-26T09:57:01.000Z","orgId":"43595867-4340-4103-b7a2-9a5208d29a85","shortName":"oracle"},"references":[{"name":"56432","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/56432"},{"name":"openSUSE-SU-2014:0174","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00105.html"},{"tags":["x_refsource_MISC"],"url":"http://hg.openjdk.java.net/jdk7u/jdk7u/hotspot/rev/839100e42498"},{"name":"56535","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/56535"},{"name":"USN-2089-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2089-1"},{"name":"102000","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/102000"},{"name":"RHSA-2014:0030","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0030.html"},{"name":"56485","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/56485"},{"name":"SSRT101454","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=139402697611681&w=2"},{"tags":["x_refsource_CONFIRM"],"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777"},{"name":"HPSBUX02972","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=139402697611681&w=2"},{"name":"RHSA-2014:0027","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0027.html"},{"name":"56486","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/56486"},{"name":"1029608","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1029608"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1051549"},{"name":"64863","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/64863"},{"name":"RHSA-2014:0026","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0026.html"},{"name":"64758","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/64758"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html"},{"name":"openSUSE-SU-2014:0180","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2014-02/msg00000.html"},{"name":"openSUSE-SU-2014:0177","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00107.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert_us@oracle.com","ID":"CVE-2013-5893","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in Oracle Java SE 7u45 and Java SE Embedded 7u45, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to improper handling of methods in MethodHandles in HotSpot JVM, which allows attackers to escape the sandbox."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"56432","refsource":"SECUNIA","url":"http://secunia.com/advisories/56432"},{"name":"openSUSE-SU-2014:0174","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00105.html"},{"name":"http://hg.openjdk.java.net/jdk7u/jdk7u/hotspot/rev/839100e42498","refsource":"MISC","url":"http://hg.openjdk.java.net/jdk7u/jdk7u/hotspot/rev/839100e42498"},{"name":"56535","refsource":"SECUNIA","url":"http://secunia.com/advisories/56535"},{"name":"USN-2089-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2089-1"},{"name":"102000","refsource":"OSVDB","url":"http://osvdb.org/102000"},{"name":"RHSA-2014:0030","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2014-0030.html"},{"name":"56485","refsource":"SECUNIA","url":"http://secunia.com/advisories/56485"},{"name":"SSRT101454","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=139402697611681&w=2"},{"name":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777","refsource":"CONFIRM","url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777"},{"name":"HPSBUX02972","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=139402697611681&w=2"},{"name":"RHSA-2014:0027","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2014-0027.html"},{"name":"56486","refsource":"SECUNIA","url":"http://secunia.com/advisories/56486"},{"name":"1029608","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1029608"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=1051549","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1051549"},{"name":"64863","refsource":"BID","url":"http://www.securityfocus.com/bid/64863"},{"name":"RHSA-2014:0026","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2014-0026.html"},{"name":"64758","refsource":"BID","url":"http://www.securityfocus.com/bid/64758"},{"name":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html"},{"name":"openSUSE-SU-2014:0180","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2014-02/msg00000.html"},{"name":"openSUSE-SU-2014:0177","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00107.html"}]}}}},"cveMetadata":{"assignerOrgId":"43595867-4340-4103-b7a2-9a5208d29a85","assignerShortName":"oracle","cveId":"CVE-2013-5893","datePublished":"2014-01-15T01:33:00.000Z","dateReserved":"2013-09-18T00:00:00.000Z","dateUpdated":"2024-08-06T17:22:31.300Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-01-15 16:08:06","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jdk:1.7.0:update45:*:*:*:*:*:*","matchCriteriaId":"45B89CBB-BF1F-4887-BD28-6D6FB77AD18A"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jre:1.7.0:update45:*:*:*:*:*:*","matchCriteriaId":"A5226952-1972-4572-9F8C-C90D89040FD3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"5893","Ordinal":"1","Title":"CVE-2013-5893","CVE":"CVE-2013-5893","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"5893","Ordinal":"1","NoteData":"Unspecified vulnerability in Oracle Java SE 7u45 and Java SE Embedded 7u45, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to improper handling of methods in MethodHandles in HotSpot JVM, which allows attackers to escape the sandbox.","Type":"Description","Title":"CVE-2013-5893"},{"CveYear":"2013","CveId":"5893","Ordinal":"2","NoteData":"2014-01-14","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"5893","Ordinal":"3","NoteData":"2016-09-26","Type":"Other","Title":"Modified"}]}}}