CVE-2013-0435: Medium severity oracle jre vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAX-WS. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper restriction of com.sun.xml.internal packages and "Better handling of UI elements."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0435?
CVE-2013-0435 has been classified as a critical vulnerability due to its potential impact on confidentiality.
How do I fix CVE-2013-0435?
To resolve CVE-2013-0435, upgrade your Java Runtime Environment or Java Development Kit to the latest version that is not impacted by this vulnerability.
Which versions are affected by CVE-2013-0435?
CVE-2013-0435 affects Oracle Java SE 7 through Update 11, Java SE 6 through Update 38, and OpenJDK versions 6 and 7.
What types of attacks does CVE-2013-0435 enable?
CVE-2013-0435 allows remote attackers to potentially gain unauthorized access to sensitive information due to unspecified vectors related to JAX-WS.
Has CVE-2013-0435 been exploited in the wild?
There are reports indicating that CVE-2013-0435 may have been exploited in targeted attacks before patches were released.