CVE-2013-3008: Critical severity IBM Java vulnerability
Published Jul 12, 2013
·Updated
Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3006.
Affected Software
9 affected componentsFixes available
redhat/java<1.7.0-ibm-1:1.7.0.5.0-1jpp.2.el5_9
1.7.0-ibm-1:1.7.0.5.0-1jpp.2.el5_9
redhat/java<1.7.0-ibm-1:1.7.0.5.0-1jpp.2.el6_4
1.7.0-ibm-1:1.7.0.5.0-1jpp.2.el6_4
IBM Java=7.0.0.0
IBM Java=7.0.1.0
IBM Java=7.0.2.0
IBM Java=7.0.3.0
IBM Java=7.0.4.0
IBM Java=7.0.4.1
IBM Java=7.0.4.2
Event History
Jul 12, 2013
CVE Published
12:00 AM
Jul 23, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3008?
CVE-2013-3008 is classified as a vulnerability that can affect confidentiality, availability, and integrity.
2
How do I fix CVE-2013-3008?
To fix CVE-2013-3008, update your IBM Java environment to version 1.7.0-ibm-1:1.7.0.5.0 or later.
3
What software is affected by CVE-2013-3008?
CVE-2013-3008 affects IBM Java 7 versions earlier than 7 SR5.
4
Can CVE-2013-3008 be exploited remotely?
Yes, CVE-2013-3008 can be exploited by remote attackers through unknown vectors.
5
What types of impacts does CVE-2013-3008 have?
The impacts of CVE-2013-3008 include potential risks to confidentiality, availability, and integrity of systems.