Skip to content
COOEY

EXPOSURES › CVE-2013-2423

CVE-2013-2423

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-2423 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedransomware

Oracle JRE's hotspot component contained an unspecified vulnerability allowing remote attackers to affect integrity, which was actively exploited in the wild.

The Oracle Java Runtime Environment (JRE) hotspot component had an unspecified vulnerability that allowed remote attackers to affect system integrity. This failure matters to DIB organizations because the JRE has a documented history of critical remote code execution vulnerabilities that have enabled ransomware outbreaks and arbitrary command execution. Organizations must ensure their Java runtimes are patched and monitored for KEV-listed vulnerabilities to prevent similar integrity compromises.

Shame score — The vulnerability was actively exploited in the wild and the JRE has a history of critical remote code execution flaws that have enabled ransomware outbreaks, indicating systemic issues in runtime security controls.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized