CVE-2013-2455: Medium severity ORACLE JRE vulnerability
It was discovered that access checks for getEnclosingClass, getEnclosingMethod and getEnclosingConstructor were not performed properly. An untrusted Java application or applet could possibly use this flaw to disclose potentially sensitive information.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2443 and CVE-2013-2452. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect access checks by the (1) getEnclosingClass, (2) getEnclosingMethod, and (3) getEnclosingConstructor methods.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2013-2455?
CVE-2013-2455 has a severity rating of medium as it allows an untrusted Java application to disclose sensitive information.
How do I fix CVE-2013-2455?
To fix CVE-2013-2455, upgrading to the patched versions of Java mentioned in the vulnerability advisory is recommended.
Which versions of Java are affected by CVE-2013-2455?
CVE-2013-2455 affects multiple versions of the Java Runtime Environment, specifically earlier updates of Java 6 and Java 7.
Can CVE-2013-2455 affect web applications?
Yes, CVE-2013-2455 can affect web applications that run untrusted Java applets, leading to potential sensitive information disclosure.
What are the recommended versions to mitigate CVE-2013-2455?
The recommended versions to mitigate CVE-2013-2455 are Java 1.6.0_75 and Java 1.7.0_25 or later.