Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2013-0443

Disclosure Date: February 02, 2013
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect validation of Diffie-Hellman keys, which allows remote attackers to conduct a “small subgroup attack” to force the use of weak session keys or obtain sensitive information about the private key.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

  • oracle,
  • sun

Products

  • jdk,
  • jdk 1.4.2,
  • jdk 1.4.2 1,
  • jdk 1.4.2 10,
  • jdk 1.4.2 11,
  • jdk 1.4.2 12,
  • jdk 1.4.2 13,
  • jdk 1.4.2 14,
  • jdk 1.4.2 15,
  • jdk 1.4.2 16,
  • jdk 1.4.2 17,
  • jdk 1.4.2 18,
  • jdk 1.4.2 19,
  • jdk 1.4.2 2,
  • jdk 1.4.2 22,
  • jdk 1.4.2 23,
  • jdk 1.4.2 25,
  • jdk 1.4.2 26,
  • jdk 1.4.2 27,
  • jdk 1.4.2 28,
  • jdk 1.4.2 29,
  • jdk 1.4.2 3,
  • jdk 1.4.2 30,
  • jdk 1.4.2 31,
  • jdk 1.4.2 32,
  • jdk 1.4.2 33,
  • jdk 1.4.2 34,
  • jdk 1.4.2 35,
  • jdk 1.4.2 36,
  • jdk 1.4.2 37,
  • jdk 1.4.2 38,
  • jdk 1.4.2 4,
  • jdk 1.4.2 5,
  • jdk 1.4.2 6,
  • jdk 1.4.2 7,
  • jdk 1.4.2 8,
  • jdk 1.4.2 9,
  • jdk 1.5.0,
  • jdk 1.6.0,
  • jdk 1.7.0,
  • jre,
  • jre 1.4.2,
  • jre 1.4.2 1,
  • jre 1.4.2 10,
  • jre 1.4.2 11,
  • jre 1.4.2 12,
  • jre 1.4.2 13,
  • jre 1.4.2 14,
  • jre 1.4.2 15,
  • jre 1.4.2 16,
  • jre 1.4.2 17,
  • jre 1.4.2 18,
  • jre 1.4.2 19,
  • jre 1.4.2 2,
  • jre 1.4.2 20,
  • jre 1.4.2 21,
  • jre 1.4.2 22,
  • jre 1.4.2 23,
  • jre 1.4.2 24,
  • jre 1.4.2 25,
  • jre 1.4.2 26,
  • jre 1.4.2 27,
  • jre 1.4.2 28,
  • jre 1.4.2 29,
  • jre 1.4.2 3,
  • jre 1.4.2 30,
  • jre 1.4.2 31,
  • jre 1.4.2 32,
  • jre 1.4.2 33,
  • jre 1.4.2 34,
  • jre 1.4.2 35,
  • jre 1.4.2 36,
  • jre 1.4.2 37,
  • jre 1.4.2 38,
  • jre 1.4.2 4,
  • jre 1.4.2 5,
  • jre 1.4.2 6,
  • jre 1.4.2 7,
  • jre 1.4.2 8,
  • jre 1.4.2 9,
  • jre 1.5.0,
  • jre 1.6.0,
  • jre 1.7.0

References

Advisory

Additional Info

Technical Analysis