CVE-2013-1475: Critical severity ORACLE JRE vulnerability
Security Explorations security and vulnerability research company reported: [1] http://seclists.org/bugtraq/2012/Sep/109
presence of a new security flaw, affecting recent Oracle Java SE 5 Update 22, Oracle Java SE 6 Update 35, and Oracle Java SE 7 Update 7 versions of Oracle Java SE software. This flaw is reported to allow complete Java security sandbox bypass.
References: [2] http://www.security-explorations.com/en/SE-2012-01.html
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.240 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "IIOP type reuse management" in ObjectStreamClass.java.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1475?
CVE-2013-1475 has been rated as having critical severity due to potential remote code execution.
How do I fix CVE-2013-1475?
To fix CVE-2013-1475, update your Oracle Java to the latest version or apply the recommended patches.
What versions are affected by CVE-2013-1475?
CVE-2013-1475 affects multiple versions of Oracle Java, including JRE and JDK 5, 6, and 7 up to certain updates.
Can CVE-2013-1475 be exploited remotely?
Yes, CVE-2013-1475 can be exploited remotely, which makes it critical for users to address the vulnerability.
What are the potential consequences of CVE-2013-1475 exploitation?
Exploitation of CVE-2013-1475 can lead to unauthorized access to the host system and full control by the attacker.