CVE-2013-2415: Low severity ORACLE JRE vulnerability
It was discovered that JAX-WS could possibly create temporary files with insecure permissions. A local attacker could use this flaw to access temporary files created by an application using JAX-WS.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows local users to affect confidentiality via vectors related to JAX-WS. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "processing of MTOM attachments" and the creation of temporary files with weak permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2415?
CVE-2013-2415 has been rated as having a moderate severity due to the potential for local attacks on insecure temporary files.
How do I fix CVE-2013-2415?
To fix CVE-2013-2415, ensure that your application is updated to a version of JAX-WS or JRE that addresses the vulnerability, such as icedtea6 version 1.11.11 or icedtea7 version 2.3.9.
Which versions are affected by CVE-2013-2415?
CVE-2013-2415 affects multiple versions of Oracle Java SE 7, including update 1 through update 15, as well as specific versions of IcedTea.
Who can be impacted by CVE-2013-2415?
Local attackers with access to the system can exploit CVE-2013-2415 to gain unauthorized access to insecure temporary files.
Is there a workaround for CVE-2013-2415 before I can update?
As a temporary measure, secure the permissions for temporary file directories used by applications to mitigate potential access risks until a patch can be applied.