CVE-2013-2412: Medium severity ORACLE JRE vulnerability
It was discovered that JConsole did not properly inform the user in case establishing an SSL connection failed. An attacker could exploit this flaw to gain access to potentially sensitive information.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Serviceability. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to insufficient indication of an SSL connection failure by JConsole, related to RMI connection dialog box.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2412?
CVE-2013-2412 is considered a critical severity vulnerability due to the potential access it offers to sensitive information.
How do I fix CVE-2013-2412?
To fix CVE-2013-2412, upgrade to the latest version of Oracle Java SE that includes the necessary security patches.
What impact does CVE-2013-2412 have on my system?
The impact of CVE-2013-2412 can include potential exposure of sensitive information if SSL connections fail without proper notification.
Which versions of Oracle JRE are affected by CVE-2013-2412?
CVE-2013-2412 affects Oracle JRE versions up to 1.7.0 update 21 and earlier.
Can CVE-2013-2412 be exploited remotely?
Yes, CVE-2013-2412 can be exploited remotely if vulnerable software is used without appropriate security measures.