Oracle Java Runtime Environment CVE-2013-2423 Security Bypass Vulnerability
BID:59162
Info
Oracle Java Runtime Environment CVE-2013-2423 Security Bypass Vulnerability
| Bugtraq ID: | 59162 |
| Class: | Unknown |
| CVE: |
CVE-2013-2423 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 16 2013 12:00AM |
| Updated: | Mar 19 2015 08:23AM |
| Credit: | Oracle |
| Vulnerable: |
Sun JRE (Windows Production Release) 1.7.0_4 Sun JRE (Windows Production Release) 1.7.0_2 Sun JRE (Windows Production Release) 1.7 Sun JRE (Solaris Production Release) 1.7.0_4 Sun JRE (Solaris Production Release) 1.7.0_2 Sun JRE (Solaris Production Release) 1.7 Sun JRE (Linux Production Release) 1.7.0_4 Sun JRE (Linux Production Release) 1.7.0_2 Sun JRE (Linux Production Release) 1.7 Sun JDK (Windows Production Release) 1.7 Sun JDK (Windows Production Release) 1.7.0_4 Sun JDK (Windows Production Release) 1.7.0_2 Sun JDK (Solaris Production Release) 1.7 Sun JDK (Solaris Production Release) 1.7.0_4 Sun JDK (Solaris Production Release) 1.7.0_2 Sun JDK (Linux Production Release) 1.7 Sun JDK (Linux Production Release) 1.7.0_4 Sun JDK (Linux Production Release) 1.7.0_2 Red Hat Fedora 17 Red Hat Enterprise Linux Workstation Supplementary 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Supplementary 5 server Red Hat Enterprise Linux Server Supplementary 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Supplementary 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Supplementary 6 Red Hat Enterprise Linux Desktop Supplementary 5 client Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 IBM Tivoli Monitoring 6.2.3 IBM Tivoli Monitoring 6.2.2 IBM Tivoli Monitoring 6.2.1 IBM Maximo Asset Management Essentials 7.5 IBM Maximo Asset Management Essentials 7.1 IBM Maximo Asset Management Essentials 6.2 IBM Maximo Asset Management 7.5 IBM Maximo Asset Management 7.1 IBM Maximo Asset Management 6.2 IBM Lotus Notes 8.5.3 IBM Lotus Notes 8.5.2 IBM Lotus Notes 8.5.1 IBM Lotus Notes 8.0.2 IBM Lotus Notes 8.5.2.3 IBM Lotus Notes 8.5.2.2 IBM Lotus Notes 8.5.2.1 IBM Lotus Notes 8.5.1.5 IBM Lotus Notes 8.5.1.4 IBM Lotus Notes 8.5.1.3 IBM Lotus Notes 8.5.1.2 IBM Lotus Notes 8.5.0.1 IBM Lotus Notes 8.5 IBM Lotus Notes 8.0.2.6 IBM Lotus Notes 8.0.2.5 IBM Lotus Notes 8.0.2.4 IBM Lotus Notes 8.0.2.3 IBM Lotus Notes 8.0.2.2 IBM Lotus Notes 8.0.2.1 IBM Lotus Notes 8.0 IBM Lotus Domino 8.5.3 IBM Lotus Domino 8.5.2 IBM Lotus Domino 8.5.1 IBM Lotus Domino 8.5 IBM Lotus Domino 8.0.2 IBM Lotus Domino 8.0.1 IBM Lotus Domino 8.5.1.1 IBM Lotus Domino 8.5.0.1 IBM Lotus Domino 8.0.2.4 IBM Lotus Domino 8.0.2.3 IBM Lotus Domino 8.0.2.2 IBM Lotus Domino 8.0.2.1 IBM Lotus Domino 8.0 IBM Java SE 7 IBM Java SE 6 IBM Java SDK 6 Gentoo Linux CentOS CentOS 6 CentOS CentOS 5 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Proactive Contact 5.0 Avaya Message Networking 5.2.1 Avaya Message Networking 5.2.4 Avaya Message Networking 5.2.3 Avaya Message Networking 5.2.2 Avaya Meeting Exchange 5.2 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.2 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: | |
Discussion
Oracle Java Runtime Environment CVE-2013-2423 Security Bypass Vulnerability
Oracle Java Runtime Environment is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass sandbox protection and perform unauthorized actions in the context of the application.
This vulnerability affects the following supported versions:
7 Update 17 and prior
Note: This BID was previously titled 'Oracle Java SE CVE-2013-2423 Remote Java Runtime Environment Vulnerability'. The title and technical details have been changed to better reflect the underlying component affected.
Oracle Java Runtime Environment is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass sandbox protection and perform unauthorized actions in the context of the application.
This vulnerability affects the following supported versions:
7 Update 17 and prior
Note: This BID was previously titled 'Oracle Java SE CVE-2013-2423 Remote Java Runtime Environment Vulnerability'. The title and technical details have been changed to better reflect the underlying component affected.
Exploit / POC
Oracle Java Runtime Environment CVE-2013-2423 Security Bypass Vulnerability
This issue is being exploited in the wild through exploit toolkits.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
The following metasploit exploit module is available:
This issue is being exploited in the wild through exploit toolkits.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
The following metasploit exploit module is available:
Solution / Fix
Oracle Java Runtime Environment CVE-2013-2423 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
The payloads delivered by the exploit kits are detected by Symantec as 'Trojan.Zbot' and 'Trojan.Horse'.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
The payloads delivered by the exploit kits are detected by Symantec as 'Trojan.Zbot' and 'Trojan.Horse'.
References
Oracle Java Runtime Environment CVE-2013-2423 Security Bypass Vulnerability
References:
References:
- "Private Exploit Pack" - new BEP featuring CVE-2013-1347 (Malware don't need Coffee)
- IBM Tivoli Composite Application Manager for Transactions Response Time 7.3.0.1 (IBM)
- Oracle April 16 2013 CPU (IBM)
- Oracle Java Critical Patch Update (April 2013) (Avaya)
- Oracle Java Homepage (Oracle)
- Security Bulletin: IBM Tivoli Composite Application Manager for Transactions aff (IBM)
- 3.2.2-TIV-ITSAMP-FP0006, Tivoli System Automation for Multiplatforms (IBM)
- 3.2.2-TIV-SAAM-FP0002, Tivoli System Automation Application Manager (IBM)
- IBM Tivoli Monitoring clients affected by vulnerabilities in IBM JRE executed un (IBM)
- Oracle Java SE Critical Patch Update Advisory - April 2013 (Oracle)
- Potential security vulnerabilities with JavaTM SDKs (IBM)
- Rational Host On-Demand clients affected by vulnerabilities in IBM JRE (IBM)
- Security Bulletin #2: IBM Tivoli System Automation Application Manager 3.2.2 (IBM)
- Security Bulletin #2: IBM Tivoli System Automation for Multiplatforms 3.2.2 (IBM)
- Security Bulletin- IBM Operational Decision Manager and WebSphere ILOG JRules (IBM)
- Security Bulletin: IBM Endpoint Manager for Remote Control is affected by multip (IBM)
- Security Bulletin: IBM Intelligent Operations Center 1.5 WebSphere Application S (IBM)
- Security Bulletin: IBM Notes & Domino fixes for multiple vulnerabilities in IBM (IBM)
- Security Bulletin: IBM Smart Analytics System 5600 is affected by vulnerabilitie (IBM)
- Security Bulletin: IBM Tivoli System Automation for Integrated Operations Manage (IBM)
- Security Bulletin: IBM Virtualization Engine TS7700 13 Multiple Java CVEs from (IBM)