← Vulnerability feed

Vulnerability record · CVE-2013-1571 · published 18 June 2013

CVE-2013-1571: Oracle Javadoc HTML frame injection allows content spoofing

Oracle · Jdk

The Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, JavaFX 2.2.21 and earlier, and OpenJDK 7 has an unspecified integrity flaw. Oracle's advisory gives no technical detail, but a third party claims it is frame injection in HTML generated by Javadoc. Because Javadoc output is often published as documentation, the flaw matters where generated pages are served or opened.

4.3 CVSS 2.0 Medium EPSS 67% · top 0.7%
4.3CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
76References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier; JavaFX 2.2.21 and earlier; and OpenJDK 7 allows remote attackers to affect integrity via unknown vectors related to Javadoc. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to frame injection in HTML that is generated by Javadoc.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityIntegrity-only impact and required user interaction limit severity, but the flaw is remotely reachable, has a patch, and shows high EPSS activity.

What it is

The Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, JavaFX 2.2.21 and earlier, and OpenJDK 7 has an unspecified integrity flaw. Oracle's advisory gives no technical detail, but a third party claims it is frame injection in HTML generated by Javadoc. Because Javadoc output is often published as documentation, the flaw matters where generated pages are served or opened.

Impact

An attacker can inject frames into Javadoc-generated HTML, altering the content a viewer sees and potentially redirecting or spoofing information. The CVSS vector shows integrity impact only, with no confidentiality or availability loss.

Attack surface

The vector is network-reachable with medium complexity and no authentication (AV:N/AC:M/Au:N). Exploitation requires the victim to view crafted or tampered Javadoc HTML, so some user interaction is implied even though the record does not state it explicitly.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at 0.669 probability (99.26th percentile). One reference is tagged Exploit and Patch, indicating public exploit-related material exists alongside the fix.

What to do

  • Apply the Oracle June 2013 CPU or later Java SE, JavaFX, and OpenJDK updates, or the relevant distribution errata (Red Hat, openSUSE, Gentoo, Mandriva, HP, IBM).
  • Regenerate Javadoc documentation with a patched JDK so published HTML no longer contains the injection flaw.
  • Restrict or remove untrusted Javadoc HTML from web servers and shared repositories until regenerated.
  • Treat Javadoc output from untrusted or third-party sources as untrusted content and serve it with a restrictive Content-Security-Policy.

Detection

  • Scan web roots and documentation repositories for Javadoc-generated HTML containing unexpected iframe or frame elements.
  • Monitor for requests to Javadoc pages that include injected frame parameters or external URLs.
  • Inventory Java SE, JavaFX, and OpenJDK versions to identify hosts still running builds older than the June 2013 CPU.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://advisories.mageia.org/MGASA-2013-0185.html
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/langtools/rev/17ee569d0c01 ExploitPatch
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.html
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.html
http://marc.info/?l=bugtraq&m=137545505800971&w=2
http://marc.info/?l=bugtraq&m=137545592101387&w=2
http://rhn.redhat.com/errata/RHSA-2013-0963.html
http://rhn.redhat.com/errata/RHSA-2013-1059.html
http://rhn.redhat.com/errata/RHSA-2013-1060.html
http://rhn.redhat.com/errata/RHSA-2013-1081.html
http://rhn.redhat.com/errata/RHSA-2013-1455.html
http://rhn.redhat.com/errata/RHSA-2013-1456.html
http://secunia.com/advisories/54154 Vendor Advisory
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www-01.ibm.com/support/docview.wss?uid=swg21642336
http://www-01.ibm.com/support/docview.wss?uid=swg21644197
http://www.kb.cert.org/vuls/id/225657 US Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2013:183
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html Vendor Advisory
http://www.securityfocus.com/bid/60634
http://www.us-cert.gov/ncas/alerts/TA13-169A US Government Resource
https://access.redhat.com/errata/RHSA-2014:0414
https://bugzilla.redhat.com/show_bug.cgi?id=973474 Patch
https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.or
https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.or
https://lists.apache.org/thread.html/re0504f08000df786e51795940501e81a5d0ae981ecca68141e87ece0%40%3Ccommits.openoffice.a
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17215
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19518
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19667
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19718
http://advisories.mageia.org/MGASA-2013-0185.html
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880

Track CVE-2013-1571 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2013-0422Oracle Java 7 JMX/MBean and Reflection API sandbox bypass RCEOracle Java 7 before Update 11 contains two flaws: the public getMBeanInstantiator method in JmxMBeanServer exposes a private MBeanInstantiator that …KEVEPSS 97%analysed9.8CVE-2012-5076Oracle Java SE JRE JAX-WS sandbox bypassCVE-2012-5076 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE 7 Update 7 and earlier, related to JA…KEVEPSS 91%analysed9.8CVE-2012-4681Oracle Java SE 7 JRE SecurityManager bypass allows remote code executionThe Java Runtime Environment in Oracle Java SE 7 Update 6 and earlier fails to properly enforce SecurityManager restrictions. A crafted applet can us…KEVEPSS 99%analysed9.8CVE-2012-1723Oracle Java SE Hotspot Improper Access Control Enables Remote Code ExecutionCVE-2012-1723 is an unspecified vulnerability in the Hotspot component of Oracle Java SE (JRE) affecting Java SE 7 update 4 and earlier, 6 update 32 …KEVEPSS 94%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2013-1571), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.