CVE-2013-1489 is an unspecified vulnerability in Oracle Java SE 7 Update 10 and 11, affecting Windows users running Internet Explorer, Firefox, Opera, and Chrome. This critical flaw allows remote attackers to bypass the "Very High" security setting in the Java Control Panel, enabling the execution of unsigned Java code without user interaction. With a CVSS score of 10.0, it poses a severe risk of complete compromise (confidentiality, integrity, and availability). While no public exploit intelligence like Metasploit modules or ExploitDB entries are noted, and community discussion is minimal, its high FAUCET Risk Score of 94/100 indicates significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update10:*:*:*:windows:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdk:1.7.0:update11:*:*:*:windows:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:windows:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:windows:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.