EXPOSURES › CVE-2013-2465
CVE-2013-2465
CRITICAL ⌖ ON CISA KEV · EXPLOITEDOracle Java SE vulnerabilities are actively exploited and linked to ransomware attacks, demonstrating a persistent risk for DIB organizations using outdated Java installations.
An unspecified vulnerability in Oracle Java SE's 2D component allows remote attackers to impact confidentiality, integrity, and availability through unknown vectors. This CVE is currently listed as actively exploited and linked to ransomware, highlighting a significant compliance risk for organizations subject to CMMC and NIST 800-171. Immediate patching and rigorous Java version control are essential.
Shame score — The ongoing exploitation of a known vulnerability, coupled with its ransomware association, points to a failure in patch management and risk mitigation, despite Oracle's frequent security updates.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to 2D
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |