Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-2423

94
FAUCET Score

CVE-2013-2423 is an unspecified vulnerability in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, affecting the Java Runtime Environment (JRE) component, specifically related to HotSpot. It allows remote attackers to impact integrity, with claims of bypassing permission checks and modifying arbitrary public final fields via reflection and type confusion. The vulnerability has a CVSS score of 3.7 (LOW) due to high attack complexity, but its EPSS score of 0.933970000 and FAUCET Risk Score of 100/100 indicate significant real-world risk. This CVE is actively exploited, listed in the KEV catalog, and has publicly available exploit code, including a Metasploit module, with substantial community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
1.7.0CPE matchmatch criteria
cpe:2.3:a:oracle:jre:1.7.0:-:*:*:*:*:*:*
1.7.0CPE matchmatch criteria
cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*
1.7.0CPE matchmatch criteria
cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:*
1.7.0CPE matchmatch criteria
cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:*
1.7.0CPE matchmatch criteria
cpe:2.3:a:oracle:jre:1.7.0:update13:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
85.33%
Probability of exploitation in next 30 days
EPSS Percentile
99.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · May 25, 2022
Metasploit: Java Applet Reflection Type Confusion Remote Code Execution · Jan 10, 2013
ExploitDB: EDB-24976 · Apr 23, 2013
This CVE's current EPSS score of 0.8533 is in the 100th percentile among its peer group of 1,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: java-1.7.0-openjdk-1:1.7.0.19-2.3.9.1.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: java-1.7.0-openjdk-1:1.7.0.19-2.3.9.1.el6_4
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.7.0-oracle-1:1.7.0.21-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.7.0-ibm-1:1.7.0.4.2-1jpp.1.el5_9
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.7.0-oracle-1:1.7.0.21-1jpp.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.7.0-ibm-1:1.7.0.4.2-1jpp.1.el6_4
View patch
oraclevendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2013-2423Moderate

OpenJDK: incorrect setter access checks in MethodHandles (Hostspot, 8009677)

Apr 16, 2013

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
blog.fuseyism.com / index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released
Broken Link
blog.spiderlabs.com / 2013/04/java-is-so-confusing.html
Not Applicable
hg.openjdk.java.net / jdk7u/jdk7u-dev/jdk/rev/b453d9be6b3f
Patch
lists.opensuse.org / opensuse-updates/2013-06/msg00099.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2013-0752.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2013-0757.html
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
security.gentoo.org / glsa/glsa-201406-32.xml
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16700
Broken Link
wiki.mageia.org / en/Support/Advisories/MGASA-2013-0130
Third Party Advisory
weblog.ikvm.net / PermaLink.aspx
Broken Link
exploit-db.com / exploits/24976
Third Party AdvisoryVDB Entry
mandriva.com / security/advisories
Third Party Advisory
oracle.com / technetwork/topics/security/javacpuapr2013-1928497.html
Vendor Advisory
ubuntu.com / usn/USN-1806-1
Third Party Advisory
us-cert.gov / ncas/alerts/TA13-107A
Third Party AdvisoryUS Government Resource