CVE-2013-5889: Critical severity oracle jre vulnerability
Oracle Java SE 6u71 and 7u51 fixes an unspecified vulnerability in the Deployment component (CVE-2013-5889). Upstream has CVSSv2 scored this issue as: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
Other sources
Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2013-5889?
CVE-2013-5889 has a CVSSv2 score of 9.3, indicating a critical severity level.
How do I fix CVE-2013-5889?
To fix CVE-2013-5889, update your Java SE to versions 6u71, 7u51, or later as specified by the vendor.
What systems are affected by CVE-2013-5889?
CVE-2013-5889 affects Oracle Java SE versions 6 and 7 prior to the specified updates.
What type of vulnerability is CVE-2013-5889?
CVE-2013-5889 is an unspecified vulnerability in the Deployment component of Oracle Java.
Does CVE-2013-5889 allow unauthenticated exploitation?
Yes, CVE-2013-5889 can be exploited by an attacker without requiring authentication.