Vulnerability Intelligence Report
CVE-2013-1489
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability.
No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:7.64%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| oracle | jdk | 1.7.0 |
| oracle | jre | 1.7.0 |
| chrome | all | |
| microsoft | internet_explorer | all |
| mozilla | firefox | all |
| opera | opera_browser | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
7.641%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Oracle · Hosted Service · USA |
| Reserved | 2013-01-30T00:00:00 |
| Published | 2013-01-31T14:10:00 |
| Patch Date | 2013-01-27 |
| Last Updated | 2024-08-06T15:04:48 |
Community Chatter & Buzz