EXPOSURES › CVE-2013-0422
CVE-2013-0422
CRITICAL ⌖ ON CISA KEV · EXPLOITEDOracle JRE applet permission flaw allowed remote attackers to execute arbitrary commands on vulnerable systems.
A vulnerability in Oracle's Java Runtime Environment allowed attackers to bypass applet permission restrictions and execute arbitrary commands on affected systems. This is a critical, actively exploited remote code execution flaw linked to ransomware campaigns, meaning DIB organizations must ensure their Java environments are patched and monitored for exploitation attempts. Failure to patch this known vulnerability exposes systems to remote compromise and violates CMMC/NIST 800-171 requirements for timely patch management.
Shame score — This is a critical, actively exploited remote code execution vulnerability in a widely deployed runtime environment that was linked to ransomware attacks, representing a severe failure in patch management and threat detection.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |