CVE-2013-2407: Medium severity ORACLE JRE vulnerability
It was discovered that the Libraries component contained certain errors related to XML security and the class loader. A remote attacker could possibly exploit this flaw to disclose potentially sensitive information and cause a denial of service.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality and availability via unknown vectors related to Libraries. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "XML security and the class loader."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2407?
CVE-2013-2407 is categorized as a high severity vulnerability that can lead to the disclosure of sensitive information or denial of service.
How do I fix CVE-2013-2407?
To mitigate CVE-2013-2407, update your Java Runtime Environment (JRE) or Java Development Kit (JDK) to the latest version released by Oracle.
What versions are affected by CVE-2013-2407?
CVE-2013-2407 affects various versions of Oracle JRE and JDK from 1.6.0 to 1.7.0 up to update 21.
Can CVE-2013-2407 be exploited remotely?
Yes, CVE-2013-2407 can be exploited remotely by attackers to access sensitive information.
What types of impacts can CVE-2013-2407 have on my system?
CVE-2013-2407 can potentially lead to denial of service and expose sensitive data stored within the affected systems.