CVE-2013-2454 is an unspecified vulnerability within the Java Runtime Environment (JRE) in Oracle Java SE (versions 7u21 and earlier, 6u45 and earlier, 5.0u45 and earlier) and OpenJDK 7, specifically impacting the JDBC component. While Oracle's description is vague, other vendors suggest it involves improper restriction of access to class packages in the SerialJavaObject class, allowing remote attackers to bypass the Java sandbox. With a CVSS score of 5.8, this vulnerability is of medium severity. It can be exploited remotely with medium attack complexity (AV:N/AC:M/Au:N), potentially leading to partial loss of confidentiality and integrity (C:P/I:P/A:N). There is no evidence of active exploitation, nor is exploit code publicly available via Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:*:update21:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:*:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.