CVE Database
/

CVE-2013-0434

Back to search

CVE-2013-0434

Published: Feb 2, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality via vectors related to JAXP. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to the public declaration of the loadPropertyFile method in the JAXP FuncSystemProperty class, which allows remote attackers to obtain sensitive information.

VendorProductVersions

n/a

n/a

affected
n/a

References

GLSA-201406-32
vendor-advisory
x_refsource_GENTOO
MDVSA-2013:095
vendor-advisory
x_refsource_MANDRIVA
SSRT101156
vendor-advisory
x_refsource_HP
TA13-032A
third-party-advisory
x_refsource_CERT
RHSA-2013:0236
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:19430
vdb-entry
signature
x_refsource_OVAL
RHSA-2013:1455
vendor-advisory
x_refsource_REDHAT
VU#858729
third-party-advisory
x_refsource_CERT-VN
SUSE-SU-2013:0478
vendor-advisory
x_refsource_SUSE
RHSA-2013:0237
vendor-advisory
x_refsource_REDHAT
HPSBUX02857
vendor-advisory
x_refsource_HP
RHSA-2013:0247
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:16528
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:19505
vdb-entry
signature
x_refsource_OVAL
HPSBMU02874
vendor-advisory
x_refsource_HP
SSRT101103
vendor-advisory
x_refsource_HP
57730
vdb-entry
x_refsource_BID
openSUSE-SU-2013:0312
vendor-advisory
x_refsource_SUSE
oval:org.mitre.oval:def:19272
vdb-entry
signature
x_refsource_OVAL
openSUSE-SU-2013:0377
vendor-advisory
x_refsource_SUSE
RHSA-2013:0246
vendor-advisory
x_refsource_REDHAT
RHSA-2013:1456
vendor-advisory
x_refsource_REDHAT
HPSBUX02864
vendor-advisory
x_refsource_HP
RHSA-2013:0245
vendor-advisory
x_refsource_REDHAT
SSRT101184
vendor-advisory
x_refsource_HP

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now