CVE-2013-2453: Medium severity ORACLE JRE vulnerability
It was discovered that the MBeanServer Introspector of the JMX component did not properly verify the package access. An untrusted Java application or applet could possibly use this flaw to bypass intended package restrictions.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect integrity via vectors related to JMX. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is due to a missing check for "package access" by the MBeanServer Introspector.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2453?
CVE-2013-2453 has a CVSS score indicating it is a high-severity vulnerability affecting certain versions of the Oracle JRE and JDK.
How do I fix CVE-2013-2453?
To fix CVE-2013-2453, users should upgrade to a patched version of the Oracle JRE or JDK that is not vulnerable.
Which versions are affected by CVE-2013-2453?
CVE-2013-2453 affects various versions of Oracle JRE and JDK, specifically up to and including version 1.7.0_update21 and certain 1.6.x versions.
Who can be impacted by CVE-2013-2453?
CVE-2013-2453 can potentially impact users of untrusted Java applications or applets that exploit this vulnerability to bypass package restrictions.
Is there a workaround for CVE-2013-2453?
There are no effective workarounds for CVE-2013-2453; the best mitigation is to update to a secure version.