CVE-2013-0429: High severity oracle jre vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue involves the creation of a single PresentationManager that is shared across multiple thread groups, which allows remote attackers to bypass Java sandbox restrictions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0429?
CVE-2013-0429 has a critical severity rating due to its potential impact on confidentiality, integrity, and availability.
How do I fix CVE-2013-0429?
To mitigate CVE-2013-0429, upgrade to the latest version of Oracle Java SE or OpenJDK that addresses this vulnerability.
What versions are affected by CVE-2013-0429?
CVE-2013-0429 affects Oracle Java SE 7 through Update 11, 6 through Update 38, and OpenJDK 6 and 7.
What types of attacks are possible with CVE-2013-0429?
CVE-2013-0429 could allow remote attackers to exploit the vulnerability via vectors related to CORBA.
Is CVE-2013-0429 easy to exploit?
Exploitation of CVE-2013-0429 is considered possible, making it important to apply patches promptly.