CVE-2013-2466: Critical severity ORACLE JRE vulnerability
Oracle Java SE 7 Update 25 fixes an unspecified vulnerability in the Deployment component (CVE-2013-2466). Upstream has CVSSv2 scored this issue as: 10.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2442 and CVE-2013-2468.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2013-2466?
CVE-2013-2466 has a CVSSv2 score of 10.0, indicating a critical vulnerability.
How do I fix CVE-2013-2466?
To remediate CVE-2013-2466, upgrade to the latest version of Oracle Java SE or an affected package that has been patched.
What type of vulnerability is CVE-2013-2466?
CVE-2013-2466 is an unspecified vulnerability in the Deployment component of Oracle Java.
Which software versions are affected by CVE-2013-2466?
CVE-2013-2466 affects various versions of Oracle JDK, JRE, and related packages up to specific update versions.
What can happen if CVE-2013-2466 is exploited?
Exploitation of CVE-2013-2466 could lead to unauthorized access to sensitive data or code execution.