HP-UX: CVE-2013-2461: Running Java7, Remote Unauthorized Access, Disclosure of Information, and Other Vulnerabilities
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
8 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | June 18, 2013 | August 11, 2017 | January 08, 2018 |
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the Oracle JRockit component in Oracle Fusion Middleware R27.7.5 and earlier and R28.2.7 and earlier; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the June and July 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass verification of XML signatures via vectors related to a "Missing check for [a] valid DOMCanonicalizationMethod canonicalization algorithm."
Scan For This Vulnerability
Use our top-rated tool to discover, prioritize, and remediate your vulnerabilities
References
Solution
hpux-update-jdk60-jdk60-comRelated Vulnerabilities
- Gentoo Linux: CVE-2013-2461: Oracle JRE/JDK: Multiple vulnerabilities
- Amazon Linux AMI: Security patch for java-1.6.0-openjdk (ALAS-2013-207) (multiple CVEs)
- DSA-2727-1 openjdk-6 -- several vulnerabilities
- ELSA-2013-0957 Critical: Oracle Linux java-1.7.0-openjdk security update
- RHSA-2013:0957: java-1.7.0-openjdk security update
- RHSA-2013:1014: java-1.6.0-openjdk security update
- Vulnerabilities deemed not relevant on Red Hat Enterprise Linux 5
- SUSE Linux Security Vulnerability: CVE-2013-2461
- USN-1908-1: OpenJDK 6 vulnerabilities
- RHSA-2013:0958: java-1.7.0-openjdk security update
- DSA-2722-1 openjdk-7 -- several vulnerabilities
- RHSA-2014:0414: java-1.6.0-sun security update
- ELSA-2013-0958 Important: Oracle Linux java-1.7.0-openjdk security update
- Apple Java security update for CVE-2013-2461
- RHSA-2013:0963: java-1.7.0-oracle security update
- Amazon Linux AMI: Security patch for java-1.7.0-openjdk (ALAS-2013-204) (multiple CVEs)
- ELSA-2013-1014 Important: Oracle Linux java-1.6.0-openjdk security update
- Vulnerabilities deemed not relevant on Red Hat Enterprise Linux 6
- USN-1907-1: OpenJDK 7 vulnerabilities
- Java CPU June 2013 Java Runtime Environment Libraries vulnerability (CVE-2013-2461)