CVE-2013-0431

oracle jre, oracle openjdk

Published 31 Jan 2013 · updated 2 Oct 2026 · Analyzed

3.7 Low · CVSS 3.1, CISA ADP

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 25 May 2022, with a remediation deadline of 15 Jun 2022 for US federal agencies. It has been used in ransomware campaigns.

Required action: Apply updates per vendor instructions.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.

References