CVE-2013-5851: Medium severity oracle jre vulnerability
Published Oct 16, 2013
·Updated
Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to JAXP.
Affected Software
34 affected components
ORACLE JRE<=1.7.0
ORACLE JRE=1.7.0
ORACLE JRE=1.7.0-update1
ORACLE JRE=1.7.0-update10
ORACLE JRE=1.7.0-update11
ORACLE JRE=1.7.0-update13
ORACLE JRE=1.7.0-update15
ORACLE JRE=1.7.0-update17
ORACLE JRE=1.7.0-update2
ORACLE JRE=1.7.0-update21
ORACLE JRE=1.7.0-update25
ORACLE JRE=1.7.0-update3
ORACLE JRE=1.7.0-update4
ORACLE JRE=1.7.0-update5
ORACLE JRE=1.7.0-update6
ORACLE JRE=1.7.0-update7
ORACLE JRE=1.7.0-update9
Oracle JDK<=1.7.0
Oracle JDK=1.7.0
Oracle JDK=1.7.0-update1
Oracle JDK=1.7.0-update10
Oracle JDK=1.7.0-update11
Oracle JDK=1.7.0-update13
Oracle JDK=1.7.0-update15
Oracle JDK=1.7.0-update17
Oracle JDK=1.7.0-update2
Oracle JDK=1.7.0-update21
Oracle JDK=1.7.0-update25
Oracle JDK=1.7.0-update3
Oracle JDK=1.7.0-update4
Oracle JDK=1.7.0-update5
Oracle JDK=1.7.0-update6
Oracle JDK=1.7.0-update7
Oracle JDK=1.7.0-update9
Event History
Oct 16, 2013
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5851?
CVE-2013-5851 is classified as a high severity vulnerability due to its potential impact on confidentiality.
2
How do I fix CVE-2013-5851?
To fix CVE-2013-5851, update your Oracle Java SE 7 to version 7u45 or later.
3
What software is affected by CVE-2013-5851?
CVE-2013-5851 affects Oracle Java SE 7u40 and earlier, including specific updates of Java Runtime Environment and Java Development Kit.
4
Can CVE-2013-5851 be exploited remotely?
Yes, CVE-2013-5851 can be exploited by remote attackers to affect confidentiality through specific JAXP vectors.
5
Is there a patch available for CVE-2013-5851?
Yes, Oracle has released a patch for CVE-2013-5851 in the form of updates for affected Java versions.