FAIL › dossier
Java Runtime Environment (JRE)
PRODUCT· dossier confidence 50%
Oracle JRE has a documented history of critical remote code execution vulnerabilities in sandbox and applet components, including CVE-2013-0431 and CVE-2013-0422, which enabled ransomware outbreaks and arbitrary command execution.
PROFILE
CategorySoftware ProductWhat they doJava Runtime Environment (JRE) is a software product that provides the runtime environment for executing Java applications.
SECURITY POSTURE
History of critical remote code execution vulnerabilities in sandbox and applet components, indicating systemic issues in runtime security controls.
Notable failures
- CVE-2013-0431 sandbox bypass RCE
- CVE-2013-0422 applet permission RCE
- CVE-2013-2423 hotspot integrity vulnerability
- CVE-2010-0840 JRE confidentiality/integrity/availability impact
Patterns: repeated unpatched edge-device RCEs; sandbox bypass vulnerabilities; applet permission flaws
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-05-25 | CVE-2013-0431 | critical | A remote sandbox bypass in Oracle JRE allowed attackers to execute arbitrary code, leading to ransomware outbreaks. |
| 2022-05-25 | CVE-2013-0422 | critical | Oracle JRE applet permission flaw allowed remote attackers to execute arbitrary commands on vulnerable systems. |
| 2022-05-25 | CVE-2010-0840 | high | An unspecified vulnerability in Oracle's Java Runtime Environment (JRE) was actively exploited in the wild, affecting confidentiality, integrity, and availability. |
| 2022-05-25 | CVE-2013-2423 | high | Oracle JRE's hotspot component contained an unspecified vulnerability allowing remote attackers to affect integrity, which was actively exploited in the wild. |
Open questions: Current patch management status for JRE · Recent security incident response effectiveness
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-02 03:45:59.538545+00:00