Vulnerability Intelligence Report
Oracle Java SE Unspecified Vulnerability
CVE-2013-2465
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:98.70%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-693 ↗CWE-693 Protection Mechanism Failure
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| oracle | jre | 1.7.0, 1.6.0, 1.5.0 |
| sun | jre | 1.6.0, 1.5.0 |
| suse | linux_enterprise_desktop | 10 |
| suse | linux_enterprise_java | 10, 11 |
| suse | linux_enterprise_server | 10, 11 |
| suse | linux_enterprise_software_development_kit | 11 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Oracle · Hosted Service · USA |
| Reserved | 2013-03-05T00:00:00 |
| Published | 2013-06-18T22:00:00 |
| Patch Date | 2013-06-18 |
| Last Updated | 2025-10-22T00:05:41 |
Community Chatter & Buzz