CVE-2013-2452: Medium severity ORACLE JRE vulnerability
It was discovered that the java.rmi.dgc.VMID class did not create entirely unique and unpredictable IDs. An untrusted Java application or applet could possibly use this flaw to disclose potentially sensitive information.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2443 and CVE-2013-2455. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "network address handling in virtual machine identifiers" and the lack of "unique and unpredictable IDs" in the java.rmi.dgc.VMID class.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2013-2452?
CVE-2013-2452 has been classified as a medium severity vulnerability.
How do I fix CVE-2013-2452?
To fix CVE-2013-2452, update the Java Runtime Environment to the latest patched version as recommended by the vendor.
What is the impact of CVE-2013-2452?
CVE-2013-2452 could allow an untrusted Java application to disclose potentially sensitive information due to non-unique and predictable IDs.
Which Java versions are affected by CVE-2013-2452?
CVE-2013-2452 affects multiple versions of the Java Runtime Environment, including versions 1.5 to 1.7.
Is CVE-2013-2452 still relevant today?
CVE-2013-2452 remains relevant as it highlights potential risks associated with older Java versions still in use.