CVE-2013-2425: Critical severity ORACLE JRE vulnerability
Published Apr 17, 2013
·Updated
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install.
Affected Software
28 affected components
ORACLE JRE<=1.7.0
ORACLE JRE=1.7.0
ORACLE JRE=1.7.0-update1
ORACLE JRE=1.7.0-update10
ORACLE JRE=1.7.0-update11
ORACLE JRE=1.7.0-update13
ORACLE JRE=1.7.0-update15
ORACLE JRE=1.7.0-update2
ORACLE JRE=1.7.0-update3
ORACLE JRE=1.7.0-update4
ORACLE JRE=1.7.0-update5
ORACLE JRE=1.7.0-update6
ORACLE JRE=1.7.0-update7
ORACLE JRE=1.7.0-update9
Oracle JDK<=1.7.0
Oracle JDK=1.7.0
Oracle JDK=1.7.0-update1
Oracle JDK=1.7.0-update10
Oracle JDK=1.7.0-update11
Oracle JDK=1.7.0-update13
Oracle JDK=1.7.0-update15
Oracle JDK=1.7.0-update2
Oracle JDK=1.7.0-update3
Oracle JDK=1.7.0-update4
Oracle JDK=1.7.0-update5
Oracle JDK=1.7.0-update6
Oracle JDK=1.7.0-update7
Oracle JDK=1.7.0-update9
Event History
Apr 17, 2013
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2425?
CVE-2013-2425 has a moderate severity rating due to its potential impact on confidentiality, integrity, and availability.
2
How do I fix CVE-2013-2425?
To fix CVE-2013-2425, update the Java Runtime Environment to a version later than update 17.
3
Which versions are affected by CVE-2013-2425?
CVE-2013-2425 affects Oracle Java SE 7 Update 17 and earlier versions.
4
Can CVE-2013-2425 be exploited remotely?
Yes, CVE-2013-2425 can be exploited remotely by attackers through unspecified vectors.
5
What products are vulnerable to CVE-2013-2425?
CVE-2013-2425 affects both Oracle Java Runtime Environment (JRE) and Oracle JDK versions up to and including 1.7.0.