CVE Database
/

CVE-2013-0424

Back to search

CVE-2013-0424

Published: Feb 2, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to RMI. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to cross-site scripting (XSS) in the sun.rmi.transport.proxy CGIHandler class that does not properly handle error messages in a (1) command or (2) port number.

VendorProductVersions

n/a

n/a

affected
n/a

References

GLSA-201406-32
vendor-advisory
x_refsource_GENTOO
MDVSA-2013:095
vendor-advisory
x_refsource_MANDRIVA
SSRT101156
vendor-advisory
x_refsource_HP
TA13-032A
third-party-advisory
x_refsource_CERT
RHSA-2013:0236
vendor-advisory
x_refsource_REDHAT
RHSA-2013:1455
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:19131
vdb-entry
signature
x_refsource_OVAL
VU#858729
third-party-advisory
x_refsource_CERT-VN
SUSE-SU-2013:0478
vendor-advisory
x_refsource_SUSE
RHSA-2013:0237
vendor-advisory
x_refsource_REDHAT
HPSBUX02857
vendor-advisory
x_refsource_HP
RHSA-2013:0247
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:19522
vdb-entry
signature
x_refsource_OVAL
HPSBMU02874
vendor-advisory
x_refsource_HP
SSRT101103
vendor-advisory
x_refsource_HP
oval:org.mitre.oval:def:19423
vdb-entry
signature
x_refsource_OVAL
openSUSE-SU-2013:0312
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2013:0377
vendor-advisory
x_refsource_SUSE
57715
vdb-entry
x_refsource_BID
RHSA-2013:0246
vendor-advisory
x_refsource_REDHAT
RHSA-2013:1456
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:16519
vdb-entry
signature
x_refsource_OVAL
HPSBUX02864
vendor-advisory
x_refsource_HP
RHSA-2013:0245
vendor-advisory
x_refsource_REDHAT
SSRT101184
vendor-advisory
x_refsource_HP

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now