CVE-2013-1489: Critical severity Oracle Jdk Windows vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1489?
CVE-2013-1489 is considered high severity due to its potential to allow attackers to bypass security controls.
How do I fix CVE-2013-1489?
To fix CVE-2013-1489, update your Oracle Java SE to a version later than Update 11.
Which versions of Oracle Java are affected by CVE-2013-1489?
CVE-2013-1489 affects Oracle Java SE 7 Update 10 and Update 11.
What types of attacks can exploit CVE-2013-1489?
CVE-2013-1489 can be exploited via remote attacks that execute untrusted Java applications.
Is CVE-2013-1489 applicable to web browsers?
Yes, CVE-2013-1489 can affect web browsers such as Internet Explorer, Firefox, Opera, and Google Chrome when running JRE.