CVE-2013-5852: High severity oracle jre vulnerability
Oracle Java SE Update 45 fixes an unspecified vulnerability in the Deployment component (CVE-2013-5852). Upstream has CVSSv2 scored this issue as: 7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
Other sources
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5787, CVE-2013-5789, CVE-2013-5824, and CVE-2013-5832.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2013-5852?
This vulnerability has a CVSSv2 score of 7.6, indicating it is classified as high severity.
How do I fix CVE-2013-5852?
To fix CVE-2013-5852, update to the latest version of Oracle Java SE, specifically Update 60 or later.
What products are affected by CVE-2013-5852?
CVE-2013-5852 affects multiple versions of Oracle Java, including Java 6 Update 45 and earlier, and Java 7 Update 45 and earlier.
What kind of attack can exploit CVE-2013-5852?
CVE-2013-5852 can potentially be exploited by attackers to execute arbitrary code on the victim’s machine.
Is CVE-2013-5852 still a threat in 2023?
While CVE-2013-5852 itself has been patched, users running vulnerable Java versions are still at risk if they haven't updated.