← Back to browse · API

CVE-2013-2423

Severity
LOW
CVSS
3.7
EPSS
0.85333
Risk score
69.67
CISA KEV
Yes
PoC
No
Published
2013-04-17
Modified
2025-10-22
First seen
2026-08-07
Aliases
EUVD-2013-2369, GHSA-WQ4H-35PF-MP23
Products
Oracle:Java Runtime Environment (JRE), n/a:n/a n/a
Sources
cisa.gov CVE-2013-2423
euvd EUVD-2013-2369

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

References