Skip to content
COOEY

EXPOSURES › CVE-2013-0431

CVE-2013-0431

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-0431 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatchedrce

A remote sandbox bypass in Oracle JRE allowed attackers to execute arbitrary code, leading to ransomware outbreaks.

The Oracle JRE sandbox bypass (CVE-2013-0431) allowed remote attackers to bypass security restrictions and execute arbitrary code, a flaw that was actively exploited in the wild and linked to ransomware campaigns. DIB organizations must ensure all Java runtimes are patched and monitored for KEV-listed vulnerabilities to prevent similar compromises. This failure highlights the critical need for rigorous patch management and continuous vulnerability monitoring.

Shame score — A known, remotely exploitable vulnerability in a widely deployed runtime was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patch management and threat intelligence integration.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized