Blog | G5 Cyber Security

CVE-2013-5838 Java flaw is back two-year later due to broken patch

The patch for the critical Java CVE-2013-5838 vulnerability released by Oracle in 2013 is ineffective and can be easily bypassed. Security Explorations firm who originally discovered the flaw confirmed that the Oracle patch is broken and an attacker can trigger the vulnerability to escape from the Java security sandbox. The new PoC exploit code works on the latest available versions of Java, including Java SE 7 Update 97, Java SE 8 Update 74 and Java SE 9 Early Access Build 108. The vulnerability was rated by Oracle 9.3 out of 10 because it could be exploited remotely by unauthenticated users.”]

Source: https://securityaffairs.co/wordpress/45294/breaking-news/cve-2013-5838-java-flaw.html

Exit mobile version