CVE-2013-2460: Critical severity ORACLE JRE vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "insufficient access checks" in the tracing component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2460?
CVE-2013-2460 has a high severity due to its potential impact on confidentiality, integrity, and availability.
How do I fix CVE-2013-2460?
To fix CVE-2013-2460, update your Java Runtime Environment to the latest version or apply the relevant patches provided by Oracle.
Which software versions are affected by CVE-2013-2460?
CVE-2013-2460 affects Oracle Java SE 7 Update 21 and earlier versions, as well as OpenJDK 7.
Can CVE-2013-2460 be exploited remotely?
Yes, CVE-2013-2460 can be exploited remotely by attackers through unspecified vectors related to Serviceability.
What components are involved in CVE-2013-2460?
CVE-2013-2460 involves the Java Runtime Environment (JRE) component of Oracle Java SE and OpenJDK.