First published: Mon Jun 17 2013(Updated: )
It was discovered that the ObjectOutputStream class did not properly perform certain access checks when handling subclasses. An untrusted Java application or applet could possibly use this flaw to disclose potentially sensitive information.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JRE | <=1.7.0 | |
Oracle JRE | =1.7.0 | |
Oracle JRE | =1.7.0-update1 | |
Oracle JRE | =1.7.0-update10 | |
Oracle JRE | =1.7.0-update11 | |
Oracle JRE | =1.7.0-update13 | |
Oracle JRE | =1.7.0-update15 | |
Oracle JRE | =1.7.0-update17 | |
Oracle JRE | =1.7.0-update2 | |
Oracle JRE | =1.7.0-update3 | |
Oracle JRE | =1.7.0-update4 | |
Oracle JRE | =1.7.0-update5 | |
Oracle JRE | =1.7.0-update6 | |
Oracle JRE | =1.7.0-update7 | |
Oracle JRE | =1.7.0-update9 | |
Oracle OpenJDK 1.8.0 | <=1.7.0 | |
Oracle OpenJDK 1.8.0 | =1.7.0 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update1 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update10 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update11 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update13 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update15 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update17 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update2 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update3 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update4 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update5 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update6 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update7 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update9 | |
Oracle JRE | <=1.6.0 | |
Oracle JRE | =1.6.0-update22 | |
Oracle JRE | =1.6.0-update23 | |
Oracle JRE | =1.6.0-update24 | |
Oracle JRE | =1.6.0-update25 | |
Oracle JRE | =1.6.0-update26 | |
Oracle JRE | =1.6.0-update27 | |
Oracle JRE | =1.6.0-update29 | |
Oracle JRE | =1.6.0-update30 | |
Oracle JRE | =1.6.0-update31 | |
Oracle JRE | =1.6.0-update32 | |
Oracle JRE | =1.6.0-update33 | |
Oracle JRE | =1.6.0-update34 | |
Oracle JRE | =1.6.0-update35 | |
Oracle JRE | =1.6.0-update37 | |
Oracle JRE | =1.6.0-update38 | |
Oracle JRE | =1.6.0-update39 | |
Oracle JRE | =1.6.0-update41 | |
Oracle JRE | =1.6.0-update43 | |
Sun Java Runtime Environment (JRE) | =1.6.0 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_1 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_10 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_11 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_12 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_13 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_14 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_15 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_16 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_17 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_18 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_19 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_2 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_20 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_21 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_3 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_4 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_5 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_6 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_7 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_9 | |
Oracle OpenJDK 1.8.0 | <=1.6.0 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update22 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update23 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update24 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update25 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update26 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update27 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update29 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update30 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update31 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update32 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update33 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update34 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update35 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update37 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update38 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update39 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update41 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update43 | |
Java Development Kit (JDK) | =1.6.0 | |
Java Development Kit (JDK) | =1.6.0-update_10 | |
Java Development Kit (JDK) | =1.6.0-update_11 | |
Java Development Kit (JDK) | =1.6.0-update_12 | |
Java Development Kit (JDK) | =1.6.0-update_13 | |
Java Development Kit (JDK) | =1.6.0-update_14 | |
Java Development Kit (JDK) | =1.6.0-update_15 | |
Java Development Kit (JDK) | =1.6.0-update_16 | |
Java Development Kit (JDK) | =1.6.0-update_17 | |
Java Development Kit (JDK) | =1.6.0-update_18 | |
Java Development Kit (JDK) | =1.6.0-update_19 | |
Java Development Kit (JDK) | =1.6.0-update_20 | |
Java Development Kit (JDK) | =1.6.0-update_21 | |
Java Development Kit (JDK) | =1.6.0-update_3 | |
Java Development Kit (JDK) | =1.6.0-update_4 | |
Java Development Kit (JDK) | =1.6.0-update_5 | |
Java Development Kit (JDK) | =1.6.0-update_6 | |
Java Development Kit (JDK) | =1.6.0-update_7 | |
Java Development Kit (JDK) | =1.6.0-update1 | |
Java Development Kit (JDK) | =1.6.0-update1_b06 | |
Java Development Kit (JDK) | =1.6.0-update2 | |
Oracle JRE | <=1.5.0 | |
Oracle JRE | =1.5.0-update36 | |
Oracle JRE | =1.5.0-update38 | |
Oracle JRE | =1.5.0-update39 | |
Oracle JRE | =1.5.0-update40 | |
Oracle JRE | =1.5.0-update41 | |
Sun Java Runtime Environment (JRE) | =1.5.0 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update1 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update10 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update11 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update12 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update13 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update14 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update15 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update16 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update17 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update18 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update19 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update2 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update20 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update21 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update22 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update23 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update24 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update25 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update26 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update27 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update28 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update29 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update3 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update31 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update33 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update4 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update5 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update6 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update7 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update8 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update9 | |
Oracle OpenJDK 1.8.0 | <=1.5.0 | |
Oracle OpenJDK 1.8.0 | =1.5.0-update36 | |
Oracle OpenJDK 1.8.0 | =1.5.0-update38 | |
Oracle OpenJDK 1.8.0 | =1.5.0-update39 | |
Oracle OpenJDK 1.8.0 | =1.5.0-update40 | |
Oracle OpenJDK 1.8.0 | =1.5.0-update41 | |
Java Development Kit (JDK) | =1.5.0 | |
Java Development Kit (JDK) | =1.5.0-update1 | |
Java Development Kit (JDK) | =1.5.0-update10 | |
Java Development Kit (JDK) | =1.5.0-update11 | |
Java Development Kit (JDK) | =1.5.0-update11_b03 | |
Java Development Kit (JDK) | =1.5.0-update12 | |
Java Development Kit (JDK) | =1.5.0-update13 | |
Java Development Kit (JDK) | =1.5.0-update14 | |
Java Development Kit (JDK) | =1.5.0-update15 | |
Java Development Kit (JDK) | =1.5.0-update16 | |
Java Development Kit (JDK) | =1.5.0-update17 | |
Java Development Kit (JDK) | =1.5.0-update18 | |
Java Development Kit (JDK) | =1.5.0-update19 | |
Java Development Kit (JDK) | =1.5.0-update2 | |
Java Development Kit (JDK) | =1.5.0-update20 | |
Java Development Kit (JDK) | =1.5.0-update21 | |
Java Development Kit (JDK) | =1.5.0-update22 | |
Java Development Kit (JDK) | =1.5.0-update23 | |
Java Development Kit (JDK) | =1.5.0-update24 | |
Java Development Kit (JDK) | =1.5.0-update25 | |
Java Development Kit (JDK) | =1.5.0-update26 | |
Java Development Kit (JDK) | =1.5.0-update27 | |
Java Development Kit (JDK) | =1.5.0-update28 | |
Java Development Kit (JDK) | =1.5.0-update29 | |
Java Development Kit (JDK) | =1.5.0-update3 | |
Java Development Kit (JDK) | =1.5.0-update31 | |
Java Development Kit (JDK) | =1.5.0-update33 | |
Java Development Kit (JDK) | =1.5.0-update4 | |
Java Development Kit (JDK) | =1.5.0-update5 | |
Java Development Kit (JDK) | =1.5.0-update6 | |
Java Development Kit (JDK) | =1.5.0-update7 | |
Java Development Kit (JDK) | =1.5.0-update7_b03 | |
Java Development Kit (JDK) | =1.5.0-update8 | |
Java Development Kit (JDK) | =1.5.0-update9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-2456 is considered medium as it allows untrusted Java applications to potentially disclose sensitive information.
To fix CVE-2013-2456, upgrade to a version of the Java Runtime Environment (JRE) or Java Development Kit (JDK) that has incorporated the necessary patches.
CVE-2013-2456 affects Oracle JRE and JDK versions 1.7.0 through 1.7.0-update17.
CVE-2013-2456 is not classified as critical, but it poses a risk that should be addressed to safeguard sensitive data.
CVE-2013-2456 is an access control vulnerability specifically in the ObjectOutputStream class of the Java Runtime Environment.