Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-0431

97
FAUCET Score

CVE-2013-0431 is an unspecified vulnerability in Oracle Java SE 7 through Update 11 and OpenJDK 7, allowing user-assisted remote attackers to bypass the Java security sandbox via JMX. This medium-severity vulnerability (CVSS 5.3) has a high FAUCET Risk Score of 100/100, indicating significant potential impact despite the low confidentiality, integrity, and availability impact noted in the CVSS vector. It is actively exploited, listed in the KEV catalog, and has known ransomware campaign usage, with Metasploit modules and ExploitDB entries available. Community discussion and media coverage are extensive, highlighting its widespread attention and the risk of exploitation, particularly by exploit kits like Blackhole.

Impacted Technologies

VendorProductVersion(s)CPE
1.7.0CPE matchmatch criteria
cpe:2.3:a:oracle:jre:1.7.0:-:*:*:*:*:*:*
1.7.0CPE matchmatch criteria
cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*
1.7.0CPE matchmatch criteria
cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:*
1.7.0CPE matchmatch criteria
cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:*
1.7.0CPE matchmatch criteria
cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
89.99%
Probability of exploitation in next 30 days
EPSS Percentile
99.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Added to KEV · May 25, 2022
Metasploit: Java Applet JMX Remote Code Execution · Jan 19, 2013
ExploitDB: EDB-24539 · Feb 25, 2013
This CVE's current EPSS score of 0.8999 is in the 100th percentile among its peer group of 23,690 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: java-1.7.0-openjdk-1:1.7.0.9-2.3.5.3.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: java-1.7.0-openjdk-1:1.7.0.9-2.3.5.3.el6_3
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.7.0-oracle-1:1.7.0.13-1jpp.1.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.7.0-ibm-1:1.7.0.4.0-1jpp.2.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.7.0-oracle-1:1.7.0.13-1jpp.3.el6_3
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.7.0-ibm-1:1.7.0.4.0-1jpp.2.el6_4
View patch
oraclevendor investigatingvia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: java-1.4.2-ibm

Vendor Advisories (1)

redhatCVE-2013-0431Moderate

OpenJDK: JMX Introspector missing package access check (JMX, 8000539, SE-2012-01 Issue 52)

Jan 27, 2013

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
arstechnica.com / security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version
Third Party Advisory
blogs.computerworld.com / malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53
Not Applicable
lists.opensuse.org / opensuse-security-announce/2013-03/msg00001.html
Third Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
rhn.redhat.com / errata/RHSA-2013-0237.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2013-0247.html
Third Party Advisory
seclists.org / fulldisclosure/2013/Jan/142
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2013/Jan/195
Mailing ListThird Party Advisory
security.gentoo.org / glsa/glsa-201406-32.xml
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16579
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19418
Broken Link
wiki.mageia.org / en/Support/Advisories/MGASA-2013-0056
Third Party Advisory
informationweek.com / security/application-security/java-hacker-uncovers-two-flaws-in-latest/240146717
Broken Link
kb.cert.org / vuls/id/858729
Third Party AdvisoryUS Government Resource
mandriva.com / security/advisories
Not Applicable
oracle.com / technetwork/topics/security/javacpufeb2013-1841061.html
Vendor Advisory
securityfocus.com / archive/1/525387/30/0/threaded
Third Party AdvisoryVDB Entry
us-cert.gov / cas/techalerts/TA13-032A.html
Third Party AdvisoryUS Government Resource