CVE-2013-2442: High severity ORACLE JRE vulnerability
Oracle Java SE 7 Update 25 fixes an unspecified vulnerability in the Deployment component (CVE-2013-2442). Upstream has CVSSv2 scored this issue as: 7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2466 and CVE-2013-2468.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2013-2442?
CVE-2013-2442 has a CVSSv2 score of 7.5, indicating a high severity.
How do I fix CVE-2013-2442?
To fix CVE-2013-2442, upgrade to the patched versions of Java specified in the remediation details.
What versions of Oracle Java are affected by CVE-2013-2442?
CVE-2013-2442 affects various versions of Oracle Java SE 6 and 7, specifically before the update 25.
Is CVE-2013-2442 a remote code execution vulnerability?
Yes, CVE-2013-2442 can potentially allow remote code execution under certain conditions.
What component is affected by CVE-2013-2442?
CVE-2013-2442 affects the Deployment component of Oracle Java.