CVE-2013-0434: Medium severity oracle jre vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.240 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAXP. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to the public declaration of the loadPropertyFile method in the JAXP FuncSystemProperty class, which allows remote attackers to obtain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0434?
CVE-2013-0434 is classified with a Moderate severity level due to its potential impact on confidentiality.
How do I fix CVE-2013-0434?
To fix CVE-2013-0434, update the Java Runtime Environment to a version released after the affected updates.
Which versions are affected by CVE-2013-0434?
CVE-2013-0434 affects Oracle Java SE 7 through Update 11, as well as several versions of Java SE 6 and earlier.
What impact does CVE-2013-0434 have on my system?
The impact of CVE-2013-0434 can lead to unauthorized access to sensitive information due to vulnerable Java components.
Can CVE-2013-0434 be exploited remotely?
Yes, CVE-2013-0434 allows remote attackers to exploit vulnerabilities through specific JAXP-related vectors.