Vulnerability record · CVE-2013-1488 · published 8 March 2013
CVE-2013-1488: Oracle Java SE JRE Reflection and JDBC Code Injection
Oracle · Jdk
The Java Runtime Environment in Oracle Java SE 7 Update 17 and earlier, plus OpenJDK 6 and 7, allows remote attackers to execute arbitrary code through unspecified vectors involving reflection, Libraries, improper toString calls, and the JDBC driver manager. The flaw was demonstrated by James Forshaw during Pwn2Own 2013, and it matters because it is remotely reachable and fully compromises confidentiality, integrity, and availability.
Description
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the JDBC driver manager, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and complete impact, combined with a very high EPSS percentile, makes this a top remediation priority despite no KEV listing.
What it is
The Java Runtime Environment in Oracle Java SE 7 Update 17 and earlier, plus OpenJDK 6 and 7, allows remote attackers to execute arbitrary code through unspecified vectors involving reflection, Libraries, improper toString calls, and the JDBC driver manager. The flaw was demonstrated by James Forshaw during Pwn2Own 2013, and it matters because it is remotely reachable and fully compromises confidentiality, integrity, and availability.
Impact
An attacker can execute arbitrary code in the context of the Java process, leading to full system compromise. Successful exploitation gives the attacker control over data and execution on the affected host.
Attack surface
The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and low complexity. The description does not specify the exact delivery path, but it is a JRE component issue that can be triggered remotely without user interaction per the vector.
Exploitation
The record is not listed in CISA KEV, but EPSS is 0.87227 (99.742 percentile), indicating a high modeled likelihood of exploitation. References include a Pwn2Own 2013 demonstration and a US Government Resource alert, confirming public technical detail and real-world exploitation in a contest setting.
What to do
- Apply the Oracle Java SE April 2013 CPU update or later, and update OpenJDK 6/7 to the fixed IcedTea releases referenced in the advisories.
- If immediate patching is not possible, disable or restrict the Java browser plugin and avoid launching untrusted Java Web Start or applet content.
- Remove or upgrade end-of-life Java 6 and Java 7 installations; migrate to a supported Java release.
- Enforce network controls that block untrusted Java applet/JNLP delivery and monitor outbound connections from Java processes.
- Verify vendor-specific patches from Red Hat, Ubuntu, SUSE, Gentoo, Mandriva, and Mageia where those distributions are in use.
Detection
- Monitor for unexpected child processes spawned by java.exe or the JRE, especially command shells or scripting interpreters.
- Alert on Java processes making outbound network connections to untrusted or unusual destinations.
- Review application and JVM logs for reflection, toString, or JDBC driver manager errors that coincide with suspicious process activity.
- Hunt for known Pwn2Own 2013 exploit artifacts or Java applet/JNLP files matching public proof-of-concept characteristics.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-1488 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-1488), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.