CVE-2013-0450: Critical severity oracle jre vulnerability
It was discovered that JMX RequiredModelMBean class did not properly check access control context. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper checks of "access control context" in the JMX RequiredModelMBean class.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0450?
CVE-2013-0450 is considered a critical vulnerability due to potential unauthorized access to sensitive information.
How do I fix CVE-2013-0450?
You can mitigate CVE-2013-0450 by updating your Java Runtime Environment or Oracle JDK to the recommended versions specified in the advisory.
Which software is affected by CVE-2013-0450?
CVE-2013-0450 affects versions of Oracle JRE and JDK 1.5.0, 1.6.0, and 1.7.0, along with specific versions of IcedTea.
What type of vulnerability is CVE-2013-0450?
CVE-2013-0450 is an access control vulnerability that allows an untrusted Java application to bypass sandbox restrictions.
When was CVE-2013-0450 disclosed?
CVE-2013-0450 was disclosed in February 2013 as part of a broader announcement about Java security vulnerabilities.