OpenJDK: JMX Introspector missing package access check (JMX, 8000539, SE-2012-01 Issue 52)
Published Jan 31, 2013 ·Due Jun 15, 2022
3.7
LOWCVSS 3.1
EPSS 90.15%
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.
Affected products
No data.
Configuration 1
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
No data.
Red Hat Enterprise Linux 5
java-1.7.0-openjdk-1:1.7.0.9-2.3.5.3.el5_9
Fixed · RHSA-2013:0247
Red Hat Enterprise Linux 6
java-1.7.0-openjdk-1:1.7.0.9-2.3.5.3.el6_3
Fixed · RHSA-2013:0247
Supplementary for Red Hat Enterprise Linux 5
java-1.7.0-ibm-1:1.7.0.4.0-1jpp.2.el5_9
Fixed · RHSA-2013:0626
Supplementary for Red Hat Enterprise Linux 5
java-1.7.0-oracle-1:1.7.0.13-1jpp.1.el5_9
Fixed · RHSA-2013:0237
Supplementary for Red Hat Enterprise Linux 6
java-1.7.0-ibm-1:1.7.0.4.0-1jpp.2.el6_4
Fixed · RHSA-2013:0626
Supplementary for Red Hat Enterprise Linux 6
java-1.7.0-oracle-1:1.7.0.13-1jpp.3.el6_3
Fixed · RHSA-2013:0237
Red Hat Enterprise Linux 5
java-1.4.2-ibm
Will not fix
Red Hat Enterprise Linux 5
java-1.5.0-ibm
Not affected
Red Hat Enterprise Linux 5
java-1.6.0-ibm
Not affected
Red Hat Enterprise Linux 5
java-1.6.0-openjdk
Not affected
Red Hat Enterprise Linux 5
java-1.6.0-sun
Not affected
Red Hat Enterprise Linux 6
java-1.5.0-ibm
Not affected
Red Hat Enterprise Linux 6
java-1.6.0-ibm
Not affected
Red Hat Enterprise Linux 6
java-1.6.0-openjdk
Not affected
Red Hat Enterprise Linux 6
java-1.6.0-sun
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | java-1.7.0-openjdk-1:1.7.0.9-2.3.5.3.el5_9 | Fixed | RHSA-2013:0247 |
| Red Hat Enterprise Linux 6 | java-1.7.0-openjdk-1:1.7.0.9-2.3.5.3.el6_3 | Fixed | RHSA-2013:0247 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.7.0-ibm-1:1.7.0.4.0-1jpp.2.el5_9 | Fixed | RHSA-2013:0626 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.7.0-oracle-1:1.7.0.13-1jpp.1.el5_9 | Fixed | RHSA-2013:0237 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.7.0-ibm-1:1.7.0.4.0-1jpp.2.el6_4 | Fixed | RHSA-2013:0626 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.7.0-oracle-1:1.7.0.13-1jpp.3.el6_3 | Fixed | RHSA-2013:0237 |
| Red Hat Enterprise Linux 5 | java-1.4.2-ibm | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | java-1.5.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 5 | java-1.6.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 5 | java-1.6.0-sun | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.5.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.6.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.6.0-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.6.0-sun | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:P/A:N
Date Added
May 25, 2022
Patch Due
Jun 15, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 14, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 90.15% (0.90150) | 99.80th | v5 (v2026.06.15) |
| Jun 15, 2026 | 89.88% (0.89880) | 99.78th | v5 (v2026.06.15) |
| May 5, 2026 | 91.00% (0.91001) | 99.64th | v4 (v2025.03.14) |
| Mar 17, 2025 | 92.44% (0.92442) | 99.73th | v4 (v2025.03.14) |
| Dec 17, 2024 | 89.94% (0.89935) | 99.04th | v3 (v2023.03.01) |
| Dec 12, 2024 | 97.03% (0.97033) | 99.81th | v3 (v2023.03.01) |
| Jun 28, 2024 | 96.90% (0.96899) | 99.72th | v3 (v2023.03.01) |
| Apr 27, 2024 | 96.77% (0.96771) | 99.67th | v3 (v2023.03.01) |
| Apr 26, 2024 | 97.30% (0.97302) | 99.86th | v3 (v2023.03.01) |
| Feb 25, 2024 | 97.41% (0.97406) | 99.92th | v3 (v2023.03.01) |
| Dec 22, 2023 | 97.47% (0.97469) | 99.96th | v3 (v2023.03.01) |
| Aug 19, 2023 | 97.49% (0.97488) | 99.95th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.47% (0.97469) | 99.92th | v3 (v2023.03.01) |
| Mar 6, 2023 | 78.06% (0.78064) | 99.43th | v2 (v2022.01.01) |
| Jan 14, 2023 | 78.06% (0.78064) | 99.42th | v2 (v2022.01.01) |
| Oct 12, 2022 | 79.01% (0.79014) | 99.45th | v2 (v2022.01.01) |
| Jul 5, 2022 | 80.21% (0.80209) | 99.48th | v2 (v2022.01.01) |
| Feb 4, 2022 | 81.60% (0.81603) | 99.46th | v2 (v2022.01.01) |
References (25)
- http://arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/ x_refsource_MISCThird Party Advisory
- http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53 x_refsource_MISCNot Applicable
- http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://marc.info/?l=bugtraq&m=136439120408139&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=136733161405818&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0237.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0247.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://seclists.org/fulldisclosure/2013/Jan/142 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2013/Jan/195 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://security.gentoo.org/glsa/glsa-201406-32.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.informationweek.com/security/application-security/java-hacker-uncovers-two-flaws-in-latest/240146717 x_refsource_MISCBroken Link
- http://www.kb.cert.org/vuls/id/858729 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 vendor-advisoryx_refsource_MANDRIVANot Applicable
- http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/archive/1/525387/30/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/cas/techalerts/TA13-032A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- https://access.redhat.com/security/cve/CVE-2013-0431 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=906447 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-0431
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16579 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19418 vdb-entrysignaturex_refsource_OVALBroken Link
- https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056 x_refsource_CONFIRMThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0431 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2013-0431
Change history (10)
- NVD
- CVSS severity changed from MEDIUM to
LOW MEDIUM → LOW
- CVSS vector changed from CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N to
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N → CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- CVSS score changed from 5.3 to
3.7 5.3 → 3.7
- CVSS severity changed from MEDIUM to
LOW
- CISA ADP
- SSVC automatable changed from yes to
no yes → no
- CVSS severity changed from MEDIUM to
LOW MEDIUM → LOW
- CVSS vector changed from CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N to
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N → CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- CVSS score changed from 5.3 to
3.7 5.3 → 3.7
- SSVC automatable changed from yes to
no
- CISA ADP
- SSVC automatable changed from no to
yes no → yes
- SSVC automatable changed from no to
yes
- CISA ADP
- SSVC automatable changed from yes to
no yes → no
- SSVC automatable changed from yes to
no
- CISA ADP
- SSVC automatable changed from no to
yes no → yes
- SSVC automatable changed from no to
yes