Oracle Java SE CVE-2013-2458 Remote Security Vulnerability
BID:60652
Info
Oracle Java SE CVE-2013-2458 Remote Security Vulnerability
| Bugtraq ID: | 60652 |
| Class: | Unknown |
| CVE: |
CVE-2013-2458 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2013 12:00AM |
| Updated: | Apr 13 2015 10:16PM |
| Credit: | Oracle |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS Ubuntu Ubuntu Linux 10.04 LTS SuSE SUSE Linux Enterprise Software Development Kit 11 SP3 SuSE SUSE Linux Enterprise Server 11 SP3 for VMware SuSE SUSE Linux Enterprise Server 11 SP3 SuSE SUSE Linux Enterprise Java 11 SP3 SuSE Suse Linux Enterprise Desktop 11 SP3 Sun JRE (Windows Production Release) 1.7 Sun JRE (Solaris Production Release) 1.7 Sun JRE (Linux Production Release) 1.7 Redhat Enterprise Linux Workstation Supplementary 6 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Server Supplementary 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Supplementary 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Supplementary 6 Redhat Enterprise Linux Desktop Supplementary 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle JRE(Windows Production Release) 1.7.0_9 Oracle JRE(Windows Production Release) 1.7.0_8 Oracle JRE(Windows Production Release) 1.7.0_17 Oracle JRE(Windows Production Release) 1.7.0_13 Oracle JRE(Windows Production Release) 1.7.0_12 Oracle JRE(Windows Production Release) 1.7.0_11 Oracle JRE(Windows Production Release) 1.7.0_10 Oracle JRE(Solaris Production Release) 1.7.0_9 Oracle JRE(Solaris Production Release) 1.7.0_8 Oracle JRE(Solaris Production Release) 1.7.0_17 Oracle JRE(Solaris Production Release) 1.7.0_13 Oracle JRE(Solaris Production Release) 1.7.0_11 Oracle JRE(Solaris Production Release) 1.7.0_10 Oracle JRE(Linux Production Release) 1.7.0_9 Oracle JRE(Linux Production Release) 1.7.0_8 Oracle JRE(Linux Production Release) 1.7.0_17 Oracle JRE(Linux Production Release) 1.7.0_11 Oracle JRE(Linux Production Release) 1.7.0_10 Oracle JRE (Windows Production Release) 1.7.0_7 Oracle JRE (Windows Production Release) 1.7.0_4 Oracle JRE (Windows Production Release) 1.7.0_21 Oracle JRE (Windows Production Release) 1.7.0_2 Oracle JRE (Solaris Production Release) 1.7.0_7 Oracle JRE (Solaris Production Release) 1.7.0_4 Oracle JRE (Solaris Production Release) 1.7.0_2 Oracle JRE (Linux Production Release) 1.7.0_7 Oracle JRE (Linux Production Release) 1.7.0_4 Oracle JRE (Linux Production Release) 1.7.0_21 Oracle JRE (Linux Production Release) 1.7.0_2 Oracle JRE (Linux Production Release) 1.7.0_13 Oracle JRE (Linux Production Release) 1.7.0_12 Oracle JDK(Windows Production Release) 1.7.0_9 Oracle JDK(Windows Production Release) 1.7.0_8 Oracle JDK(Windows Production Release) 1.7.0_21 Oracle JDK(Windows Production Release) 1.7.0_17 Oracle JDK(Windows Production Release) 1.7.0_13 Oracle JDK(Windows Production Release) 1.7.0_12 Oracle JDK(Windows Production Release) 1.7.0_11 Oracle JDK(Windows Production Release) 1.7.0_10 Oracle JDK(Solaris Production Release) 1.7.0_9 Oracle JDK(Solaris Production Release) 1.7.0_8 Oracle JDK(Solaris Production Release) 1.7.0_21 Oracle JDK(Solaris Production Release) 1.7.0_13 Oracle JDK(Solaris Production Release) 1.7.0_12 Oracle JDK(Linux Production Release) 1.7.0_9 Oracle JDK(Linux Production Release) 1.7.0_8 Oracle JDK(Linux Production Release) 1.7.0_21 Oracle JDK(Linux Production Release) 1.7.0_17 Oracle JDK(Linux Production Release) 1.7.0_11 Oracle JDK(Linux Production Release) 1.7.0_10 Oracle JDK(Linux Production Release) 1.6.0_43 Oracle JDK (Windows Production Release) 1.7 Oracle JDK (Windows Production Release) 1.7.0_7 Oracle JDK (Windows Production Release) 1.7.0_4 Oracle JDK (Windows Production Release) 1.7.0_2 Oracle JDK (Solaris Production Release) 1.7 Oracle JDK (Solaris Production Release) 1.7.0_7 Oracle JDK (Solaris Production Release) 1.7.0_4 Oracle JDK (Solaris Production Release) 1.7.0_2 Oracle JDK (Solaris Production Release) 1.7.0_11 Oracle JDK (Solaris Production Release) 1.7.0_10 Oracle JDK (Linux Production Release) 1.7 Oracle JDK (Linux Production Release) 1.7.0_7 Oracle JDK (Linux Production Release) 1.7.0_4 Oracle JDK (Linux Production Release) 1.7.0_2 Oracle JDK (Linux Production Release) 1.7.0_13 Oracle JDK (Linux Production Release) 1.7.0_12 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 IBM WebSphere Real Time 3 SR4-FP2 IBM WebSphere Real Time 2.0 IBM WebSphere Operational Decision Management 7.5.0.0 IBM WebSphere Message Broker 6.1 IBM WebSphere ILOG JRules 7.1 IBM Virtualization Engine TS7700 0 IBM Tivoli System Automation for Integrated Operations Management 2.1.1 IBM Tivoli System Automation for Integrated Operations Management 2.1 IBM Tivoli Storage Productivity Center 5.1.1 IBM Tivoli Storage Productivity Center 5.1 IBM Tivoli Storage Productivity Center 5.1.1.1 IBM Tivoli Storage Productivity Center 5.1.1.0 IBM Tivoli Storage Productivity Center 4.2.2 FP3 IBM Tivoli Storage Productivity Center 4.2.1 IBM Tivoli Storage Productivity Center 4.2.0 IBM Tivoli Storage Productivity Center 4.1 IBM Tivoli Provisioning Manager 7.1.1 IBM Tivoli Monitoring 6.3 IBM Tivoli Monitoring 6.2.3 Fix Pack 3 IBM Tivoli Monitoring 6.2.3 2 IBM Tivoli Monitoring 6.2.3 IBM Tivoli Monitoring 6.2.2 9 IBM Tivoli Monitoring 6.2.2 IBM Tivoli Monitoring 6.2.1 Fix Pack 04 IBM Tivoli Monitoring 6.2.1 IBM Tivoli Monitoring 6.2 Fix Pack 03 IBM Tivoli Monitoring 6.2 IBM Tivoli Monitoring 6.3.0.1 IBM Tivoli Monitoring 6.2.3.1 IBM Tivoli Monitoring 6.2.2 FP6 IBM Tivoli Monitoring 6.2.2 FixPack 4 IBM Tivoli Composite Application Manager for Transactions 7.3.0.1 IBM Tivoli Composite Application Manager for Transactions 7.3.0 IBM Tivoli Composite Application Manager for Transactions 7.2.0.2 IBM Tivoli Composite Application Manager for Transactions 7.2.0.1 IBM Tivoli Composite Application Manager for Transactions 7.2.0 IBM Tivoli Composite Application Manager for Transactions 7.1.0.2 IBM Tivoli Composite Application Manager for Transactions 7.1.0.1 IBM Tivoli Composite Application Manager for Transactions 7.1.0 IBM Tivoli Application Dependency Discovery Manager 7.2.2 IBM Tivoli Application Dependency Discovery Manager 7.2.1 3 IBM Tivoli Application Dependency Discovery Manager 7.2.1 2 IBM Tivoli Application Dependency Discovery Manager 7.2.1 1 IBM Tivoli Application Dependency Discovery Manager 7.2.1 IBM Tivoli Application Dependency Discovery Manager 7.2 IBM Tivoli Application Dependency Discovery Manager 7.2.1.5 IBM Tivoli Application Dependency Discovery Manager 7.2.1.4 IBM System Storage Productivity Center 0 IBM Smart Analytics System 5600 9.7 IBM Service Delivery Manager 7.2.4 IBM Service Delivery Manager 7.2.2 IBM Service Delivery Manager 7.2.1 IBM Operational Decision Manager 8.5 IBM Operational Decision Manager 8.0 IBM Maximo Asset Management 7.2.1 IBM Maximo Asset Management 7.1.1 IBM Maximo Asset Management 6.2.8 IBM Maximo Asset Management 6.2.7 IBM Maximo Asset Management 6.2.6 IBM Maximo Asset Management 6.2.5 IBM Maximo Asset Management 6.2.4 IBM Maximo Asset Management 6.2.3 IBM Maximo Asset Management 6.2.2 IBM Maximo Asset Management 6.2.1 IBM Maximo Asset Management 7.5 IBM Maximo Asset Management 7.2 IBM Maximo Asset Management 6.2 IBM Lotus Notes 8.5.3 IBM Lotus Notes 8.5.2 IBM Lotus Notes 8.5.1 IBM Lotus Notes 8.0.2 IBM Lotus Notes 9.0 IBM Lotus Notes 8.5.2.3 IBM Lotus Notes 8.5.2.2 IBM Lotus Notes 8.5.2.1 IBM Lotus Notes 8.5.1.5 IBM Lotus Notes 8.5.1.4 IBM Lotus Notes 8.5.1.3 IBM Lotus Notes 8.5.1.2 IBM Lotus Notes 8.5.0.1 IBM Lotus Notes 8.5 IBM Lotus Notes 8.0.2.6 IBM Lotus Notes 8.0.2.5 IBM Lotus Notes 8.0.2.4 IBM Lotus Notes 8.0.2.3 IBM Lotus Notes 8.0.2.2 IBM Lotus Notes 8.0.2.1 IBM Lotus Notes 8.0 IBM Lotus Domino 8.5.4 IBM Lotus Domino 8.5.3 IBM Lotus Domino 8.5.2 IBM Lotus Domino 8.5.1 IBM Lotus Domino 8.5 IBM Lotus Domino 8.0.2 IBM Lotus Domino 8.0.1 IBM Lotus Domino 9.0 IBM Lotus Domino 8.5.1.1 IBM Lotus Domino 8.5.0.1 IBM Lotus Domino 8.0.2.4 IBM Lotus Domino 8.0.2.3 IBM Lotus Domino 8.0.2.2 IBM Lotus Domino 8.0.2.1 IBM Lotus Domino 8.0 IBM Java SE 1.4.2 IBM Java SE 7 IBM Java SE 6 IBM Java SE 5.0 IBM Java SDK 1.4.2 IBM Java SDK 7 SR4-FP2 IBM Java SDK 7 IBM Java SDK 6.0.1 SR5-FP2 IBM Java SDK 6 SR13-FP2 IBM Java SDK 6 IBM Java SDK 5.0 SR16-FP2 IBM Java SDK 5 IBM Java SDK 1.4.2 SR13-FP17 IBM Integration Bus 9.0.0.0 IBM i V5R4 IBM i 7.1 IBM i 6.1 IBM Flex System Manager Types 8734 1.3 IBM Flex System Manager Types 8734 1.1.0 IBM Flex System Manager Types 8731 1.3 IBM Flex System Manager Types 8731 1.1.0 IBM Flex System Manager Types 7955 1.3 IBM Flex System Manager Types 7955 1.1.0 IBM Cloudburst 2.1.1 IBM Cloudburst 2.1 IBM Cloudburst 1.2 HP HP-UX B.11.31 Hitachi uCosminexus Service Platform 8 Hitachi uCosminexus Service Architect 8 Hitachi uCosminexus Operator 8 Hitachi uCosminexus Developer 09-00 (Linux) Hitachi uCosminexus Client 8 Hitachi uCosminexus Application Server 09-00 Hitachi Cosminexus Studio 5 Hitachi Cosminexus Studio 4.0 Hitachi Cosminexus Server - Web Edition 4 Hitachi Cosminexus Server - Standard Edition 4 Hitachi Cosminexus Developer 6.0 Hitachi Cosminexus Developer 5 Hitachi Cosminexus Client 6 Hitachi Cosminexus Application Server 6.0 Hitachi Cosminexus Application Server 5.0 Hitachi Cosminexus 9.0 Hitachi Cosminexus 8.0 Hitachi Cosminexus 7.0 Gentoo Linux CentOS CentOS 6 CentOS CentOS 5 Avaya Voice Portal 5.1.3 Avaya Voice Portal 5.1.2 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 SP3 Avaya Voice Portal 5.1 SP2 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya Proactive Contact 5.1 Avaya Proactive Contact 5.0 Avaya Messaging Application Server 5.2.1 Avaya Message Networking 6.2.0 Avaya Meeting Exchange 6.2 Avaya Meeting Exchange 6.0 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 Avaya IR 4.0 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya CMS r17 Avaya CMS R16.3 Avaya CMS R16 Avaya CMS r15 Avaya Aura System Manager 6.3 Avaya Aura System Manager 6.2 SP3 Avaya Aura System Manager 6.2 Avaya Aura System Manager 6.1.5 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 SP2 Avaya Aura System Manager 6.1 Sp1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura Session Manager 6.2.1 Avaya Aura Session Manager 6.1.5 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.0.1 Avaya Aura Session Manager 6.3 Avaya Aura Session Manager 6.2.2 Avaya Aura Session Manager 6.2 SP1 Avaya Aura Session Manager 6.2 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2.1 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Presence Services 6.1.2 Avaya Aura Presence Services 6.1.1 Avaya Aura Presence Services 6.1 SP1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Messaging 6.1.1 Avaya Aura Messaging 6.2 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0.2 Avaya Aura Experience Portal 6.0.1 Avaya Aura Experience Portal 6.0 Avaya Aura Conferencing 7.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Application Server 5300 SIP Core 3.0 Avaya Aura Application Server 5300 SIP Core 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.2 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.4 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: |
IBM WebSphere Real Time 3 SR5 IBM WebSphere Message Broker 6.1.0.12 IBM Virtualization Engine TS7700 8.31.0.89 IBM Tivoli System Automation for Integrated Operations Management 2.1.1.5 IBM Tivoli Storage Productivity Center 5.1.1.2 IBM Tivoli Storage Productivity Center 4.2.2.170 (FP4) IBM Java SDK 7 SR5 IBM Java SDK 6.0.1 SR6 IBM Java SDK 6 SR14 IBM Java SDK 5.0 SR16-FP3 IBM Java SDK 1.4.2 SR13-FP18 IBM Integration Bus 9.0.0.1 |
Discussion
Oracle Java SE CVE-2013-2458 Remote Security Vulnerability
Oracle Java SE is prone to a remote vulnerability in Java Runtime Environment.
The vulnerability can be exploited over multiple protocols. This issue affects the 'Deployment' sub-component.
This vulnerability affects the following supported versions:
7 Update 21
Oracle Java SE is prone to a remote vulnerability in Java Runtime Environment.
The vulnerability can be exploited over multiple protocols. This issue affects the 'Deployment' sub-component.
This vulnerability affects the following supported versions:
7 Update 21
Exploit / POC
Oracle Java SE CVE-2013-2458 Remote Security Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Java SE CVE-2013-2458 Remote Security Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle Java SE CVE-2013-2458 Remote Security Vulnerability
References:
References:
- IBM Java Security alerts (IBM)
- IBM Tivoli Composite Application Manager for Transactions Response Time 7.3.0.1 (IBM)
- Oracle Homepage (Oracle)
- HPSBUX02907 rev.1 - HP-UX Running Java7, Remote Unauthorized Access, Disclosure (HP)
- HS13-015: Multiple Vulnerabilities in Cosminexus (Hitachi)
- IBM Tivoli Monitoring clients affected by vulnerabilities in IBM JRE executed un (IBM)
- IBM Tivoli Monitoring clients affected by vulnerabilities in IBM JRE executed un (IBM)
- IBM Tivoli Monitoring clients affected by vulnerabilities in IBM JREexecuted und (IBM)
- IBM WebSphere Message Broker and IBM Integration Bus Security Vulnerability (IBM)
- Multiple vulnerabilities in the IBM i Java SDK (IBM)
- Oracle Java Critical Patch Update (June 2013) (Avaya)
- Oracle Java SE Critical Patch Update Advisory - June 2013 (Oracle)
- Security Bulletin: Flex System Manager (FSM) ? June 2013 Java Vulnerabilities (IBM)
- Security Bulletin: IBM Notes & Domino fixes for multiple vulnerabilities in IBM (IBM)
- Security Bulletin: IBM Operational Decision Manager and WebSphere ILOG JRules: M (IBM)
- Security Bulletin: IBM Smart Analytics System 5600 is affected by vulnerabilitie (IBM)
- Security Bulletin: IBM Tivoli System Automation for Integrated Operations Manage (IBM)
- Security Bulletin: IBM Virtualization Engine TS7700 - Multiple Java CVEs from Ju (IBM)
- Security Bulletin: Multiple vulnerabilities in IBM WebSphere Real Time (IBM)
- Security Bulletin: Multiple vulnerabilities in the IBM Java SDK (IBM)
- Security Bulletin: Potential security vulnerabilities with JavaTM SDKs (IBM)
- Security Bulletin: Tivoli Storage Productivity Center - Oracle CPU June 2013 (IBM)
- TADDM 7.2.2.0 and 7.2.1.5: Vulnerabilities in embedded JRE (IBM)
- Tivoli Provisioning Manager, Interim Fix 7.1.1-TIV-TPM-IF00009 (IBM)
- USN-1908-1: OpenJDK 6 vulnerabilities (Ubuntu)
- Vulnerabilities in IBM Tivoli Monitoring affecting IBM CloudBurst (IBM)
- Vulnerabilities in IBM Tivoli Monitoring affecting IBM Service Delivery Manager (IBM)