CVE-2013-5797: Low severity oracle java se 7 vulnerability
A flaw was found in the way javadoc (Java API Documentation Generator) created a JavaScript code used to set browser window title when navigating between pages of the generated API documentation. An input from user was not properly escaped before being used as part of the JavaScript string. A specially crafted input could "break out" of the JS string and execute arbitrary JavaScript in the context of the domain that hosts generated API documentation, allowing a Cross-Site Scripting attacks.
Other sources
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and JavaFX 2.2.40 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Javadoc.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2013-5797?
The severity of CVE-2013-5797 is classified as high due to its potential for cross-site scripting attacks.
How do I fix CVE-2013-5797?
To fix CVE-2013-5797, upgrade to the patched versions of Java as specified in the advisory for your affected environment.
What software is affected by CVE-2013-5797?
CVE-2013-5797 affects multiple versions of Java, including specific updates for Red Hat's Java packages.
What types of attacks can exploit CVE-2013-5797?
CVE-2013-5797 can be exploited for cross-site scripting (XSS) attacks, enabling attackers to execute arbitrary JavaScript in the user's browser.
When was CVE-2013-5797 disclosed?
CVE-2013-5797 was disclosed in October 2013 during Oracle's Critical Patch Update.