← Global Threat Landscape

CVE-2013-2423

CWE-284

Medium

67.1

RPS

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

Source: NVD

Signals

CVSS
3.7
Low · v3.1
EPSS
85.21%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since May 2022
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-284
Published
17 Apr 2013
Last modified 22 Apr 2026

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2013-2423

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2013-2423 · RPS 67.1 · DevSecure Intelligence