First published: Sat Feb 02 2013(Updated: )
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAXP. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to the public declaration of the loadPropertyFile method in the JAXP FuncSystemProperty class, which allows remote attackers to obtain sensitive information.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JRE | =1.7.0 | |
Oracle JRE | =1.7.0-update1 | |
Oracle JRE | =1.7.0-update10 | |
Oracle JRE | =1.7.0-update11 | |
Oracle JRE | =1.7.0-update2 | |
Oracle JRE | =1.7.0-update3 | |
Oracle JRE | =1.7.0-update4 | |
Oracle JRE | =1.7.0-update5 | |
Oracle JRE | =1.7.0-update6 | |
Oracle JRE | =1.7.0-update7 | |
Oracle JRE | =1.7.0-update9 | |
Oracle Java SE 7 | =1.7.0 | |
Oracle Java SE 7 | =1.7.0-update1 | |
Oracle Java SE 7 | =1.7.0-update10 | |
Oracle Java SE 7 | =1.7.0-update11 | |
Oracle Java SE 7 | =1.7.0-update2 | |
Oracle Java SE 7 | =1.7.0-update3 | |
Oracle Java SE 7 | =1.7.0-update4 | |
Oracle Java SE 7 | =1.7.0-update5 | |
Oracle Java SE 7 | =1.7.0-update6 | |
Oracle Java SE 7 | =1.7.0-update7 | |
Oracle Java SE 7 | =1.7.0-update9 | |
Oracle JRE | =1.6.0-update22 | |
Oracle JRE | =1.6.0-update23 | |
Oracle JRE | =1.6.0-update24 | |
Oracle JRE | =1.6.0-update25 | |
Oracle JRE | =1.6.0-update26 | |
Oracle JRE | =1.6.0-update27 | |
Oracle JRE | =1.6.0-update29 | |
Oracle JRE | =1.6.0-update30 | |
Oracle JRE | =1.6.0-update31 | |
Oracle JRE | =1.6.0-update32 | |
Oracle JRE | =1.6.0-update33 | |
Oracle JRE | =1.6.0-update34 | |
Oracle JRE | =1.6.0-update35 | |
Oracle JRE | =1.6.0-update37 | |
Oracle JRE | =1.6.0-update38 | |
Sun Java Runtime Environment (JRE) | =1.6.0 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_1 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_10 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_11 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_12 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_13 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_14 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_15 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_16 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_17 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_18 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_19 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_2 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_20 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_21 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_3 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_4 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_5 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_6 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_7 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_9 | |
Oracle Java SE 7 | =1.6.0-update22 | |
Oracle Java SE 7 | =1.6.0-update23 | |
Oracle Java SE 7 | =1.6.0-update24 | |
Oracle Java SE 7 | =1.6.0-update25 | |
Oracle Java SE 7 | =1.6.0-update26 | |
Oracle Java SE 7 | =1.6.0-update27 | |
Oracle Java SE 7 | =1.6.0-update29 | |
Oracle Java SE 7 | =1.6.0-update30 | |
Oracle Java SE 7 | =1.6.0-update31 | |
Oracle Java SE 7 | =1.6.0-update32 | |
Oracle Java SE 7 | =1.6.0-update33 | |
Oracle Java SE 7 | =1.6.0-update34 | |
Oracle Java SE 7 | =1.6.0-update35 | |
Oracle Java SE 7 | =1.6.0-update37 | |
Oracle Java SE 7 | =1.6.0-update38 | |
Java Development Kit (JDK) | =1.6.0 | |
Java Development Kit (JDK) | =1.6.0-update_10 | |
Java Development Kit (JDK) | =1.6.0-update_11 | |
Java Development Kit (JDK) | =1.6.0-update_12 | |
Java Development Kit (JDK) | =1.6.0-update_13 | |
Java Development Kit (JDK) | =1.6.0-update_14 | |
Java Development Kit (JDK) | =1.6.0-update_15 | |
Java Development Kit (JDK) | =1.6.0-update_16 | |
Java Development Kit (JDK) | =1.6.0-update_17 | |
Java Development Kit (JDK) | =1.6.0-update_18 | |
Java Development Kit (JDK) | =1.6.0-update_19 | |
Java Development Kit (JDK) | =1.6.0-update_20 | |
Java Development Kit (JDK) | =1.6.0-update_21 | |
Java Development Kit (JDK) | =1.6.0-update_3 | |
Java Development Kit (JDK) | =1.6.0-update_4 | |
Java Development Kit (JDK) | =1.6.0-update_5 | |
Java Development Kit (JDK) | =1.6.0-update_6 | |
Java Development Kit (JDK) | =1.6.0-update_7 | |
Java Development Kit (JDK) | =1.6.0-update1 | |
Java Development Kit (JDK) | =1.6.0-update1_b06 | |
Java Development Kit (JDK) | =1.6.0-update2 | |
Oracle JRE | =1.5.0-update36 | |
Oracle JRE | =1.5.0-update38 | |
Sun Java Runtime Environment (JRE) | =1.5.0 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update1 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update10 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update11 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update12 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update13 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update14 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update15 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update16 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update17 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update18 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update19 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update2 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update20 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update21 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update22 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update23 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update24 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update25 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update26 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update27 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update28 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update29 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update3 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update31 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update33 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update4 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update5 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update6 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update7 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update8 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update9 | |
Oracle Java SE 7 | =1.5.0-update36 | |
Oracle Java SE 7 | =1.5.0-update38 | |
Java Development Kit (JDK) | =1.5.0 | |
Java Development Kit (JDK) | =1.5.0-update1 | |
Java Development Kit (JDK) | =1.5.0-update10 | |
Java Development Kit (JDK) | =1.5.0-update11 | |
Java Development Kit (JDK) | =1.5.0-update11_b03 | |
Java Development Kit (JDK) | =1.5.0-update12 | |
Java Development Kit (JDK) | =1.5.0-update13 | |
Java Development Kit (JDK) | =1.5.0-update14 | |
Java Development Kit (JDK) | =1.5.0-update15 | |
Java Development Kit (JDK) | =1.5.0-update16 | |
Java Development Kit (JDK) | =1.5.0-update17 | |
Java Development Kit (JDK) | =1.5.0-update18 | |
Java Development Kit (JDK) | =1.5.0-update19 | |
Java Development Kit (JDK) | =1.5.0-update2 | |
Java Development Kit (JDK) | =1.5.0-update20 | |
Java Development Kit (JDK) | =1.5.0-update21 | |
Java Development Kit (JDK) | =1.5.0-update22 | |
Java Development Kit (JDK) | =1.5.0-update23 | |
Java Development Kit (JDK) | =1.5.0-update24 | |
Java Development Kit (JDK) | =1.5.0-update25 | |
Java Development Kit (JDK) | =1.5.0-update26 | |
Java Development Kit (JDK) | =1.5.0-update27 | |
Java Development Kit (JDK) | =1.5.0-update28 | |
Java Development Kit (JDK) | =1.5.0-update29 | |
Java Development Kit (JDK) | =1.5.0-update3 | |
Java Development Kit (JDK) | =1.5.0-update31 | |
Java Development Kit (JDK) | =1.5.0-update33 | |
Java Development Kit (JDK) | =1.5.0-update4 | |
Java Development Kit (JDK) | =1.5.0-update5 | |
Java Development Kit (JDK) | =1.5.0-update6 | |
Java Development Kit (JDK) | =1.5.0-update7 | |
Java Development Kit (JDK) | =1.5.0-update7_b03 | |
Java Development Kit (JDK) | =1.5.0-update8 | |
Java Development Kit (JDK) | =1.5.0-update9 | |
Oracle JRE | <=1.4.2_40 | |
Oracle JRE | =1.4.2_38 | |
Sun Java Runtime Environment (JRE) | =1.4.2 | |
Sun Java Runtime Environment (JRE) | =1.4.2_1 | |
Sun Java Runtime Environment (JRE) | =1.4.2_2 | |
Sun Java Runtime Environment (JRE) | =1.4.2_3 | |
Sun Java Runtime Environment (JRE) | =1.4.2_4 | |
Sun Java Runtime Environment (JRE) | =1.4.2_5 | |
Sun Java Runtime Environment (JRE) | =1.4.2_6 | |
Sun Java Runtime Environment (JRE) | =1.4.2_7 | |
Sun Java Runtime Environment (JRE) | =1.4.2_8 | |
Sun Java Runtime Environment (JRE) | =1.4.2_9 | |
Sun Java Runtime Environment (JRE) | =1.4.2_10 | |
Sun Java Runtime Environment (JRE) | =1.4.2_11 | |
Sun Java Runtime Environment (JRE) | =1.4.2_12 | |
Sun Java Runtime Environment (JRE) | =1.4.2_13 | |
Sun Java Runtime Environment (JRE) | =1.4.2_14 | |
Sun Java Runtime Environment (JRE) | =1.4.2_15 | |
Sun Java Runtime Environment (JRE) | =1.4.2_16 | |
Sun Java Runtime Environment (JRE) | =1.4.2_17 | |
Sun Java Runtime Environment (JRE) | =1.4.2_18 | |
Sun Java Runtime Environment (JRE) | =1.4.2_19 | |
Sun Java Runtime Environment (JRE) | =1.4.2_20 | |
Sun Java Runtime Environment (JRE) | =1.4.2_21 | |
Sun Java Runtime Environment (JRE) | =1.4.2_22 | |
Sun Java Runtime Environment (JRE) | =1.4.2_23 | |
Sun Java Runtime Environment (JRE) | =1.4.2_24 | |
Sun Java Runtime Environment (JRE) | =1.4.2_25 | |
Sun Java Runtime Environment (JRE) | =1.4.2_26 | |
Sun Java Runtime Environment (JRE) | =1.4.2_27 | |
Sun Java Runtime Environment (JRE) | =1.4.2_28 | |
Sun Java Runtime Environment (JRE) | =1.4.2_29 | |
Sun Java Runtime Environment (JRE) | =1.4.2_30 | |
Sun Java Runtime Environment (JRE) | =1.4.2_31 | |
Sun Java Runtime Environment (JRE) | =1.4.2_32 | |
Sun Java Runtime Environment (JRE) | =1.4.2_33 | |
Sun Java Runtime Environment (JRE) | =1.4.2_34 | |
Sun Java Runtime Environment (JRE) | =1.4.2_35 | |
Sun Java Runtime Environment (JRE) | =1.4.2_36 | |
Sun Java Runtime Environment (JRE) | =1.4.2_37 | |
Oracle Java SE 7 | <=1.4.2_40 | |
Oracle Java SE 7 | =1.4.2_38 | |
Java Development Kit (JDK) | =1.4.2 | |
Java Development Kit (JDK) | =1.4.2_1 | |
Java Development Kit (JDK) | =1.4.2_2 | |
Java Development Kit (JDK) | =1.4.2_3 | |
Java Development Kit (JDK) | =1.4.2_4 | |
Java Development Kit (JDK) | =1.4.2_5 | |
Java Development Kit (JDK) | =1.4.2_6 | |
Java Development Kit (JDK) | =1.4.2_7 | |
Java Development Kit (JDK) | =1.4.2_8 | |
Java Development Kit (JDK) | =1.4.2_9 | |
Java Development Kit (JDK) | =1.4.2_10 | |
Java Development Kit (JDK) | =1.4.2_11 | |
Java Development Kit (JDK) | =1.4.2_12 | |
Java Development Kit (JDK) | =1.4.2_13 | |
Java Development Kit (JDK) | =1.4.2_14 | |
Java Development Kit (JDK) | =1.4.2_15 | |
Java Development Kit (JDK) | =1.4.2_16 | |
Java Development Kit (JDK) | =1.4.2_17 | |
Java Development Kit (JDK) | =1.4.2_18 | |
Java Development Kit (JDK) | =1.4.2_19 | |
Java Development Kit (JDK) | =1.4.2_22 | |
Java Development Kit (JDK) | =1.4.2_23 | |
Java Development Kit (JDK) | =1.4.2_25 | |
Java Development Kit (JDK) | =1.4.2_26 | |
Java Development Kit (JDK) | =1.4.2_27 | |
Java Development Kit (JDK) | =1.4.2_28 | |
Java Development Kit (JDK) | =1.4.2_29 | |
Java Development Kit (JDK) | =1.4.2_30 | |
Java Development Kit (JDK) | =1.4.2_31 | |
Java Development Kit (JDK) | =1.4.2_32 | |
Java Development Kit (JDK) | =1.4.2_33 | |
Java Development Kit (JDK) | =1.4.2_34 | |
Java Development Kit (JDK) | =1.4.2_35 | |
Java Development Kit (JDK) | =1.4.2_36 | |
Java Development Kit (JDK) | =1.4.2_37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0434 is classified with a Moderate severity level due to its potential impact on confidentiality.
To fix CVE-2013-0434, update the Java Runtime Environment to a version released after the affected updates.
CVE-2013-0434 affects Oracle Java SE 7 through Update 11, as well as several versions of Java SE 6 and earlier.
The impact of CVE-2013-0434 can lead to unauthorized access to sensitive information due to vulnerable Java components.
Yes, CVE-2013-0434 allows remote attackers to exploit vulnerabilities through specific JAXP-related vectors.