Oracle Java SE 7 <= Update 11 Multiple Vulnerabilities (February 2013 CPU)

Critical Nessus Network Monitor Plugin ID 6685

Synopsis

The remote Windows host contains a programming platform that is affected by multiple vulnerabilities

Description

This version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is 7 Update 11 or earlier and is, therefore, potentially affected by security issues in the following components :

- 2D

- AWT

- Beans

- CORBA

- Deployment

- Install

- JavaFX

- JAXP

- JAX-WS

- JMX

- JSSE

- Libraries

- Networking

- RMI

- Scripting

- Sound

Solution

Update to JDK / JRE 7 Update 13 or later and, if necessary, remove any affected versions.

See Also

http://archives.neohapsis.com/archives/fulldisclosure/2013-02/0013.html

http://www.security-explorations.com/en/SE-2012-01-details.html

http://www.nessus.org/u?a915dbbd

Plugin Details

Severity: Critical

ID: 6685

Family: Web Clients

Published: 2012/02/06

Modified: 2016/01/19

Dependencies: 1735, 8314

Nessus ID: 64454

Risk Information

Risk Factor: Critical

CVSSv2

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSSv3

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS3#E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:oracle:java_se

Patch Publication Date: 2013/02/01

Vulnerability Publication Date: 2013/01/19

Exploitable With

Metasploit (Java Applet JMX Remote Code Execution)

Reference Information

CVE: CVE-2012-1541, CVE-2012-3213, CVE-2012-3342, CVE-2013-0351, CVE-2013-0409, CVE-2013-0419, CVE-2013-0423, CVE-2013-0424, CVE-2013-0425, CVE-2013-0426, CVE-2013-0427, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0431, CVE-2013-0432, CVE-2013-0433, CVE-2013-0434, CVE-2013-0435, CVE-2013-0437, CVE-2013-0438, CVE-2013-0440, CVE-2013-0441, CVE-2013-0442, CVE-2013-0443, CVE-2013-0444, CVE-2013-0445, CVE-2013-0446, CVE-2013-0448, CVE-2013-0449, CVE-2013-0450, CVE-2013-1473, CVE-2013-1475, CVE-2013-1476, CVE-2013-1478, CVE-2013-1479, CVE-2013-1480, CVE-2013-1489

BID: 57681, 57686, 57687, 57689, 57691, 57692, 57694, 57696, 57697, 57699, 57700, 57701, 57702, 57703, 57704, 57706, 57707, 57708, 57709, 57710, 57711, 57713, 57714, 57715, 57716, 57720, 57722, 57723, 57724, 57726, 57727, 57728, 57729, 57730, 57731