CVE-2013-2423: Oracle JRE Unspecified Vulnerability
java.lang.invoke.MethodHandles did not perform access checks correctly. An untrusted Java application or applet could use this to set value of a final field.
Other sources
Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.
— CISA
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/icedtea7to a version that resolves this vulnerability.Fixed in 2.3.9
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2423?
CVE-2013-2423 is categorized as a vulnerability that affects the integrity of the Java Runtime Environment.
How do I fix CVE-2013-2423?
To fix CVE-2013-2423, upgrade to the latest supported version of Oracle Java Runtime Environment or OpenJDK.
Which versions are affected by CVE-2013-2423?
CVE-2013-2423 affects Oracle Java SE 7 Update 17 and earlier, as well as OpenJDK 7.
Can CVE-2013-2423 be exploited remotely?
Yes, CVE-2013-2423 can be exploited by remote attackers to impact system integrity.
What components are involved in CVE-2013-2423?
CVE-2013-2423 specifically involves the hotspot component of the Java Runtime Environment.