CVE-2013-2468: Critical severity ORACLE JRE vulnerability
Oracle Java SE 7 Update 25 fixes an unspecified vulnerability in the Deployment component (CVE-2013-2468). Upstream has CVSSv2 scored this issue as: 10.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2442 and CVE-2013-2466.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2013-2468?
CVE-2013-2468 has a CVSSv2 score of 10.0, indicating a critical vulnerability.
How do I fix CVE-2013-2468?
To fix CVE-2013-2468, upgrade to the patched version of Java as specified in the available security updates.
What components are affected by CVE-2013-2468?
CVE-2013-2468 specifically affects the Deployment component of Oracle Java.
Which versions of Java are vulnerable to CVE-2013-2468?
Versions of Java prior to the latest update that addresses CVE-2013-2468 are vulnerable.
Are there workarounds for CVE-2013-2468?
While updates are the best recourse, disabling Java in browsers can serve as a temporary workaround for CVE-2013-2468.