CVE-2013-1488 describes a critical remote code execution vulnerability affecting Oracle Java SE 7 Update 17 and earlier, as well as OpenJDK 6 and 7. This flaw, demonstrated during Pwn2Own 2013, stems from unspecified vectors involving reflection, Libraries, improper toString calls, and the JDBC driver manager. With a CVSS score of 10.0, it presents a severe risk, allowing unauthenticated attackers to achieve complete compromise of confidentiality, integrity, and availability over the network with low attack complexity. While not listed on CISA's KEV catalog, a Metasploit module exists for this vulnerability, indicating readily available exploit code, though it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update17:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update17:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.