CVE Tools

CVE-2013-0422

Exploited in the wild. In CISA KEV since 2022‑05‑25. A vendor fix is available.

Published Updated Sources: CVE.org, NVD, BDU

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check whether any system in your business is running Oracle Java 7 (look for “1.7” in your Java version output) and whether it is older than “Update 11”.
  2. If Java 7 is present and older than Update 11, plan an immediate upgrade to Oracle Java 7 Update 11 or later using your vendor’s supported method (for managed Linux packages, upgrade the Java/JRE packages that your OS vendor provides).
  3. If you cannot upgrade right away, temporarily disable or restrict Java 7 usage for internet-facing services (e.g., stop services that use that Java version and prevent remote access to those services) until the update is applied.
  4. Confirm after updating that the Java version is Update 11 or later and review web/app server logs for suspicious activity related to Java/JMX/Reflection exploitation patterns.

What it is

From the CVE record

Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114. CVE-2013-0422 covers both the JMX/MBean and Reflection API issues. NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks. NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11. If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.

In plain language

Written by AI from the record

CVE-2013-0422 is a critical remote code execution bug in older Oracle Java 7 releases (before Update 11); if your business runs Java 7 that’s not fully updated, you should treat this as an urgent risk.

CVE-2013-0422 (KEV) covers multiple remote code execution weaknesses in Oracle Java 7 before Update 11, including misuse of the JMX MBean instantiation path and a Reflection API security-check bypass; attackers can run code without needing local access, and it has been used in real-world ransomware campaigns.

If you're affected

  • Full server takeover
  • Ransomware installation risk
  • Data theft from local files
  • Service disruption

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS99th
CISA KEV
CISA KEV

Listed as exploited in the wild since 2022-05-25.

US federal agencies must remediate by 2022-06-15.

Known use in ransomware campaigns.

Apply updates per vendor instructions.
Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

97% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

6 events over 4914 days, from the signal feeds we watch.

  1. OpenVAS check added
  2. Patch availablerecord updated
  3. Added to CISA KEVransomware campaign
  4. Publishedweakness classified

Affected products

Technical detail

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Scored 9.8 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Red Hat Inc., not every advisory. This one: actively exploited.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store