Vulnerability Name:

CVE-2013-5902 (CCN-90343)

Assigned:2013-09-18
Published:2014-01-14
Updated:2022-05-13
Summary:Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2014-0410, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (REDHAT CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Unknown
References:Source: MITRE
Type: CNA
CVE-2013-5902

Source: HP
Type: UNKNOWN
SSRT101454

Source: HP
Type: UNKNOWN
SSRT101455

Source: OSVDB
Type: UNKNOWN
102011

Source: CCN
Type: RHSA-2014-0030
Critical: java-1.7.0-oracle security update

Source: REDHAT
Type: UNKNOWN
RHSA-2014:0030

Source: SECUNIA
Type: UNKNOWN
56485

Source: SECUNIA
Type: UNKNOWN
56535

Source: CCN
Type: Oracle Web site
Oracle Critical Patch Update Advisory - January 2014

Source: CONFIRM
Type: Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html

Source: BID
Type: UNKNOWN
64758

Source: CCN
Type: BID-64758
RETIRED: Oracle January 2014 Critical Patch Update Multiple Vulnerabilities

Source: BID
Type: UNKNOWN
64923

Source: CCN
Type: BID-64923
Oracle Java SE CVE-2013-5902 Remote Security Vulnerability

Source: SECTRACK
Type: UNKNOWN
1029608

Source: REDHAT
Type: UNKNOWN
RHSA-2014:0414

Source: XF
Type: UNKNOWN
oracle-cpujan2014-cve20135902(90343)

Source: XF
Type: UNKNOWN
oracle-cpujan2014-cve20135902(90343)

Source: CONFIRM
Type: UNKNOWN
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:jre:1.7.0:update45:*:*:*:*:*:*
  • OR cpe:/a:oracle:jdk:1.7.0:update45:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:oracle:jdk:1.6.0:update65:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.6.0:update65:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:rhel_extras_oracle_java:5:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:rhel_extras_oracle_java:6:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:jdk:1.7.0:update45:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.7.0:update45:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:com.redhat.rhsa:def:20140414
    P
    RHSA-2014:0414: java-1.6.0-sun security update (Important)
    2017-12-15
    oval:org.cisecurity:def:1545
    V
    HPE HP-UX running CIFS Server (Samba), Remote Denial of Service (DoS), Disclosure of Information, Unauthorized Access
    2017-01-06
    oval:org.mitre.oval:def:24739
    P
    ELSA-2014:0414: java-1.6.0-sun security update (Important)
    2014-07-21
    oval:org.mitre.oval:def:24557
    P
    RHSA-2014:0414: java-1.6.0-sun security update (Important)
    2014-06-09
    oval:org.mitre.oval:def:24172
    P
    ELSA-2014:0030: java-1.7.0-oracle security update (Critical)
    2014-05-26
    oval:org.mitre.oval:def:22415
    P
    RHSA-2014:0030: java-1.7.0-oracle security update (Critical)
    2014-05-12
    oval:org.mitre.oval:def:22349
    V
    Vulnerability in Java SE 6u65 and Java SE 7u45 component of Oracle Java SE (subcomponent: Deployment)
    2014-03-03
    oval:com.redhat.rhsa:def:20140030
    P
    RHSA-2014:0030: java-1.7.0-oracle security update (Critical)
    2014-01-15
    oval:com.ubuntu.precise:def:20135902000
    V
    CVE-2013-5902 on Ubuntu 12.04 LTS (precise) - high.
    2014-01-15
    BACK
    oracle jre 1.7.0 update45
    oracle jdk 1.7.0 update45
    oracle jdk 1.6.0 update65
    oracle jre 1.6.0 update65
    oracle jdk 1.7.0 update45
    oracle jre 1.7.0 update45