CVE-2013-0431 is an unspecified vulnerability in Oracle Java SE 7 through Update 11 and OpenJDK 7, allowing user-assisted remote attackers to bypass the Java security sandbox via JMX. This medium-severity vulnerability (CVSS 5.3) has a high FAUCET Risk Score of 100/100, indicating significant potential impact despite the low confidentiality, integrity, and availability impact noted in the CVSS vector. It is actively exploited, listed in the KEV catalog, and has known ransomware campaign usage, with Metasploit modules and ExploitDB entries available. Community discussion and media coverage are extensive, highlighting its widespread attention and the risk of exploitation, particularly by exploit kits like Blackhole.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:-:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.