← Vulnerability feed

Vulnerability record · CVE-2013-1488 · published 8 March 2013

CVE-2013-1488: Oracle Java SE JRE Reflection and JDBC Code Injection

Oracle · Jdk

The Java Runtime Environment in Oracle Java SE 7 Update 17 and earlier, plus OpenJDK 6 and 7, allows remote attackers to execute arbitrary code through unspecified vectors involving reflection, Libraries, improper toString calls, and the JDBC driver manager. The flaw was demonstrated by James Forshaw during Pwn2Own 2013, and it matters because it is remotely reachable and fully compromises confidentiality, integrity, and availability.

10.0 CVSS 2.0 High EPSS 87% · top 0.3% CWE-94 · Code injection
10.0CVSS 2.0 base score
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
44References
16 Jun 2026Last modified by NVD

Description

The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the JDBC driver manager, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and complete impact, combined with a very high EPSS percentile, makes this a top remediation priority despite no KEV listing.

What it is

The Java Runtime Environment in Oracle Java SE 7 Update 17 and earlier, plus OpenJDK 6 and 7, allows remote attackers to execute arbitrary code through unspecified vectors involving reflection, Libraries, improper toString calls, and the JDBC driver manager. The flaw was demonstrated by James Forshaw during Pwn2Own 2013, and it matters because it is remotely reachable and fully compromises confidentiality, integrity, and availability.

Impact

An attacker can execute arbitrary code in the context of the Java process, leading to full system compromise. Successful exploitation gives the attacker control over data and execution on the affected host.

Attack surface

The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and low complexity. The description does not specify the exact delivery path, but it is a JRE component issue that can be triggered remotely without user interaction per the vector.

Exploitation

The record is not listed in CISA KEV, but EPSS is 0.87227 (99.742 percentile), indicating a high modeled likelihood of exploitation. References include a Pwn2Own 2013 demonstration and a US Government Resource alert, confirming public technical detail and real-world exploitation in a contest setting.

What to do

  • Apply the Oracle Java SE April 2013 CPU update or later, and update OpenJDK 6/7 to the fixed IcedTea releases referenced in the advisories.
  • If immediate patching is not possible, disable or restrict the Java browser plugin and avoid launching untrusted Java Web Start or applet content.
  • Remove or upgrade end-of-life Java 6 and Java 7 installations; migrate to a supported Java release.
  • Enforce network controls that block untrusted Java applet/JNLP delivery and monitor outbound connections from Java processes.
  • Verify vendor-specific patches from Red Hat, Ubuntu, SUSE, Gentoo, Mandriva, and Mageia where those distributions are in use.

Detection

  • Monitor for unexpected child processes spawned by java.exe or the JRE, especially command shells or scripting interpreters.
  • Alert on Java processes making outbound network connections to untrusted or unusual destinations.
  • Review application and JVM logs for reflection, toString, or JDBC driver manager errors that coincide with suspicious process activity.
  • Hunt for known Pwn2Own 2013 exploit artifacts or Java applet/JNLP files matching public proof-of-concept characteristics.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/
http://blog.fuseyism.com/index.php/2013/04/25/security-icedtea-1-11-11-1-12-5-for-openjdk-6-released/
http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/a19614a3dabb
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00007.html
http://lists.opensuse.org/opensuse-updates/2013-05/msg00017.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00099.html
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022796.html
http://rhn.redhat.com/errata/RHSA-2013-0752.html
http://rhn.redhat.com/errata/RHSA-2013-0757.html
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2013:145
http://www.mandriva.com/security/advisories?name=MDVSA-2013:161
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
http://www.ubuntu.com/usn/USN-1806-1
http://www.us-cert.gov/ncas/alerts/TA13-107A US Government Resource
http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/
https://bugzilla.redhat.com/show_bug.cgi?id=920247
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16511
https://twitter.com/thezdi/status/309425888188043264
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0124
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0130
http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/
http://blog.fuseyism.com/index.php/2013/04/25/security-icedtea-1-11-11-1-12-5-for-openjdk-6-released/
http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/a19614a3dabb
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00007.html
http://lists.opensuse.org/opensuse-updates/2013-05/msg00017.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00099.html
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022796.html
http://rhn.redhat.com/errata/RHSA-2013-0752.html
http://rhn.redhat.com/errata/RHSA-2013-0757.html
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2013:145
http://www.mandriva.com/security/advisories?name=MDVSA-2013:161
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
http://www.ubuntu.com/usn/USN-1806-1
http://www.us-cert.gov/ncas/alerts/TA13-107A US Government Resource
http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/
https://bugzilla.redhat.com/show_bug.cgi?id=920247

Track CVE-2013-1488 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2013-0422Oracle Java 7 JMX/MBean and Reflection API sandbox bypass RCEOracle Java 7 before Update 11 contains two flaws: the public getMBeanInstantiator method in JmxMBeanServer exposes a private MBeanInstantiator that …KEVEPSS 97%analysed9.8CVE-2012-5076Oracle Java SE JRE JAX-WS sandbox bypassCVE-2012-5076 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE 7 Update 7 and earlier, related to JA…KEVEPSS 91%analysed9.8CVE-2012-4681Oracle Java SE 7 JRE SecurityManager bypass allows remote code executionThe Java Runtime Environment in Oracle Java SE 7 Update 6 and earlier fails to properly enforce SecurityManager restrictions. A crafted applet can us…KEVEPSS 99%analysed9.8CVE-2012-1723Oracle Java SE Hotspot Improper Access Control Enables Remote Code ExecutionCVE-2012-1723 is an unspecified vulnerability in the Hotspot component of Oracle Java SE (JRE) affecting Java SE 7 update 4 and earlier, 6 update 32 …KEVEPSS 94%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2013-1488), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.