CVE-2013-5840: Medium severity oracle java se 7 vulnerability
It was discovered that getDeclaringClass() method implementation did not perform class loader package access checks. In certain configurations, an untrusted Java application or applet could possibly use this flaw to bypass certain Java sandbox restrictions.
Other sources
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5840?
The severity of CVE-2013-5840 is classified as medium due to its impact on the Java sandbox environment.
How do I fix CVE-2013-5840?
To fix CVE-2013-5840, upgrade to a non-vulnerable version of the affected software listed in the advisory.
What versions are affected by CVE-2013-5840?
CVE-2013-5840 affects multiple versions of Oracle JDK, Oracle JRE, and IcedTea as specified in the vulnerability description.
What type of vulnerability is CVE-2013-5840?
CVE-2013-5840 is a class loader package access vulnerability that could lead to bypassing security restrictions.
Can exploiting CVE-2013-5840 allow remote code execution?
Exploiting CVE-2013-5840 could potentially allow an untrusted Java application to execute code beyond restricted sandbox boundaries.