Oracle Java Runtime Environment CVE-2013-0422 Multiple Remote Code Execution Vulnerabilities
BID:57246
Info
Oracle Java Runtime Environment CVE-2013-0422 Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 57246 |
| Class: | Unknown |
| CVE: |
CVE-2013-0422 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 10 2013 12:00AM |
| Updated: | Mar 19 2015 08:15AM |
| Credit: | Kafeine |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server for VMware 11 SP2 SuSE SUSE Linux Enterprise Server 11 SP2 Sun JDK (Windows Production Release) 1.7 Sun JDK (Windows Production Release) 1.7.0_4 Sun JDK (Windows Production Release) 1.7.0_2 Sun JDK (Solaris Production Release) 1.7 Sun JDK (Solaris Production Release) 1.7.0_4 Sun JDK (Solaris Production Release) 1.7.0_2 Sun JDK (Linux Production Release) 1.7 Sun JDK (Linux Production Release) 1.7.0_4 Sun JDK (Linux Production Release) 1.7.0_2 Red Hat Fedora 17 Red Hat Fedora 16 Red Hat Enterprise Linux Workstation Supplementary 6 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Server Supplementary 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Supplementary 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Supplementary 6 Red Hat Enterprise Linux Desktop Supplementary 5 client Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 IBM Maximo Asset Management Essentials 7.5 IBM Maximo Asset Management Essentials 7.1 IBM Maximo Asset Management 7.5 IBM Maximo Asset Management 7.1 IBM Maximo Asset Management 6.2 IBM Java SE 7 SR1 Gentoo Linux CentOS CentOS 5 |
| Not Vulnerable: | |
Discussion
Oracle Java Runtime Environment CVE-2013-0422 Multiple Remote Code Execution Vulnerabilities
Oracle Java Runtime Environment is prone to multiple remote code execution vulnerabilities.
An attacker can exploit these issues to execute arbitrary code in the context of the application.
Versions prior to Oracle JRE 1.7.0 Update 11 are vulnerable.
Oracle Java Runtime Environment is prone to multiple remote code execution vulnerabilities.
An attacker can exploit these issues to execute arbitrary code in the context of the application.
Versions prior to Oracle JRE 1.7.0 Update 11 are vulnerable.
Exploit / POC
Oracle Java Runtime Environment CVE-2013-0422 Multiple Remote Code Execution Vulnerabilities
This issue is actively being exploited in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
This issue is actively being exploited in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
Oracle Java Runtime Environment CVE-2013-0422 Multiple Remote Code Execution Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Oracle Java Runtime Environment CVE-2013-0422 Multiple Remote Code Execution Vulnerabilities
References:
References: