Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.
References
Link Providers
http://arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/ cve-icon cve-icon
http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53 cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=136439120408139&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=136733161405818&w=2 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0237.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0247.html cve-icon cve-icon
http://seclists.org/fulldisclosure/2013/Jan/142 cve-icon cve-icon
http://seclists.org/fulldisclosure/2013/Jan/195 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-201406-32.xml cve-icon cve-icon
http://www.informationweek.com/security/application-security/java-hacker-uncovers-two-flaws-in-latest/240146717 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/858729 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html cve-icon cve-icon cve-icon
http://www.securityfocus.com/archive/1/525387/30/0/threaded cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA13-032A.html cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2013-0431 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16579 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19418 cve-icon cve-icon
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056 cve-icon cve-icon
https://www.cisa.gov/known-exploited-vulnerabilities-catalog cve-icon
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0431 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2013-0431 cve-icon
History

Wed, 22 Oct 2025 01:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Mon, 10 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

kev

{'dateAdded': '2022-05-25'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 23:45:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published: 2013-01-31T14:10:00.000Z

Updated: 2025-10-22T00:05:44.308Z

Reserved: 2012-12-07T00:00:00.000Z

Link: CVE-2013-0431

cve-icon Vulnrichment

Updated: 2024-08-06T14:25:10.309Z

cve-icon NVD

Status : Deferred

Published: 2013-01-31T14:55:01.327

Modified: 2025-10-22T01:15:46.403

Link: CVE-2013-0431

cve-icon Redhat

Severity : Moderate

Publid Date: 2013-01-27T00:00:00Z

Links: CVE-2013-0431 - Bugzilla