Vulnerability record · CVE-2013-1571 · published 18 June 2013
CVE-2013-1571: Oracle Javadoc HTML frame injection allows content spoofing
Oracle · Jdk
The Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, JavaFX 2.2.21 and earlier, and OpenJDK 7 has an unspecified integrity flaw. Oracle's advisory gives no technical detail, but a third party claims it is frame injection in HTML generated by Javadoc. Because Javadoc output is often published as documentation, the flaw matters where generated pages are served or opened.
Description
Unspecified vulnerability in the Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier; JavaFX 2.2.21 and earlier; and OpenJDK 7 allows remote attackers to affect integrity via unknown vectors related to Javadoc. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to frame injection in HTML that is generated by Javadoc.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityIntegrity-only impact and required user interaction limit severity, but the flaw is remotely reachable, has a patch, and shows high EPSS activity.
What it is
The Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, JavaFX 2.2.21 and earlier, and OpenJDK 7 has an unspecified integrity flaw. Oracle's advisory gives no technical detail, but a third party claims it is frame injection in HTML generated by Javadoc. Because Javadoc output is often published as documentation, the flaw matters where generated pages are served or opened.
Impact
An attacker can inject frames into Javadoc-generated HTML, altering the content a viewer sees and potentially redirecting or spoofing information. The CVSS vector shows integrity impact only, with no confidentiality or availability loss.
Attack surface
The vector is network-reachable with medium complexity and no authentication (AV:N/AC:M/Au:N). Exploitation requires the victim to view crafted or tampered Javadoc HTML, so some user interaction is implied even though the record does not state it explicitly.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at 0.669 probability (99.26th percentile). One reference is tagged Exploit and Patch, indicating public exploit-related material exists alongside the fix.
What to do
- Apply the Oracle June 2013 CPU or later Java SE, JavaFX, and OpenJDK updates, or the relevant distribution errata (Red Hat, openSUSE, Gentoo, Mandriva, HP, IBM).
- Regenerate Javadoc documentation with a patched JDK so published HTML no longer contains the injection flaw.
- Restrict or remove untrusted Javadoc HTML from web servers and shared repositories until regenerated.
- Treat Javadoc output from untrusted or third-party sources as untrusted content and serve it with a restrictive Content-Security-Policy.
Detection
- Scan web roots and documentation repositories for Javadoc-generated HTML containing unexpected iframe or frame elements.
- Monitor for requests to Javadoc pages that include injected frame parameters or external URLs.
- Inventory Java SE, JavaFX, and OpenJDK versions to identify hosts still running builds older than the June 2013 CPU.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-1571 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-1571), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.