CVE-2013-0444

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to insufficient checks for cached results by the Java Beans MethodFinder, which might allow attackers to access methods that should only be accessible to privileged code.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
8.026

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Java jdk (x64) 7.0(x64)Windows
Multiple vulnerabilities affected in Java jdk 7.0Windows
Multiple vulnerabilities affected in Java jre (x64) 7.0(x64)Windows
Multiple vulnerabilities affected in Java jre 7.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234