Vulnerability Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 13 and earlier, 6 Update 39 and earlier, and 5.0 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Jre | 1.7.0 |
| Oracle | Jdk | 1.7.0 |
| Sun | Jre | 1.6.0 |
| Sun | Jdk | 1.6.0 |
References
- http://blog.fuseyism.com/index.php/2013/02/20/security-icedtea-2-1-6-2-2-6-2-3-7
- http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00002.html
- http://marc.info/?l=bugtraq&m=136439120408139&w=2
- http://marc.info/?l=bugtraq&m=136733161405818&w=2
- http://rhn.redhat.com/errata/RHSA-2013-1455.html
- http://rhn.redhat.com/errata/RHSA-2013-1456.html
- http://security.gentoo.org/glsa/glsa-201406-32.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:095
- http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.hPatchVendor Advisory
- http://www.securityfocus.com/bid/58029
- http://www.ubuntu.com/usn/USN-1735-1
- http://www.us-cert.gov/cas/techalerts/TA13-051A.htmlUS Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
FAQ
What is CVE-2013-1486?
CVE-2013-1486 is a vulnerability with a CVSS score of 10.0 (HIGH). Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 13 and earlier, 6 Update 39 and earlier, and 5.0 Update 39 and earlier allows remote attackers to a...
How severe is CVE-2013-1486?
CVE-2013-1486 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-1486?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Jre, Oracle Jdk, Sun Jre, Sun Jdk.