Skip to content
COOEY

EXPOSURES › CVE-2013-0422

CVE-2013-0422

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-0422 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Oracle JRE applet permission flaw allowed remote attackers to execute arbitrary commands on vulnerable systems.

A vulnerability in Oracle's Java Runtime Environment allowed attackers to bypass applet permission restrictions and execute arbitrary commands on affected systems. This is a critical, actively exploited remote code execution flaw linked to ransomware campaigns, meaning DIB organizations must ensure their Java environments are patched and monitored for exploitation attempts. Failure to patch this known vulnerability exposes systems to remote compromise and violates CMMC/NIST 800-171 requirements for timely patch management.

Shame score — This is a critical, actively exploited remote code execution vulnerability in a widely deployed runtime environment that was linked to ransomware attacks, representing a severe failure in patch management and threat detection.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized