← Vulnerability feed

Vulnerability record · CVE-2013-2460 · published 18 June 2013

CVE-2013-2460: Oracle Java SE JRE Serviceability sandbox bypass

Oracle · Jre

CVE-2013-2460 is an unspecified vulnerability in the Serviceability component of Oracle Java SE 7 Update 21 and earlier and OpenJDK 7. Oracle's own advisory gives no technical detail, but a third-party vendor claims it allows remote attackers to bypass the Java sandbox through insufficient access checks in the tracing component. Because it is a sandbox escape in a widely deployed runtime, it matters for any host running untrusted Java applets or web-start applications.

9.3 CVSS 2.0 High EPSS 70% · top 0.6%
9.3CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "insufficient access checks" in the tracing component.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityIt is a remotely reachable sandbox escape with complete confidentiality, integrity and availability impact and a very high EPSS score, though it is not in KEV and the technical details are unspecified.

What it is

CVE-2013-2460 is an unspecified vulnerability in the Serviceability component of Oracle Java SE 7 Update 21 and earlier and OpenJDK 7. Oracle's own advisory gives no technical detail, but a third-party vendor claims it allows remote attackers to bypass the Java sandbox through insufficient access checks in the tracing component. Because it is a sandbox escape in a widely deployed runtime, it matters for any host running untrusted Java applets or web-start applications.

Impact

An attacker who gets code running inside the Java sandbox can escape it and gain the privileges of the JVM process, affecting confidentiality, integrity and availability of the host. In practice this means arbitrary code execution as the user running the browser or Java application.

Attack surface

The CVSS vector AV:N/AC:M/Au:N/C:C/I:C/A:C indicates it is reachable over the network with no authentication, but requires medium complexity, consistent with a victim visiting a malicious or compromised page that loads a crafted applet. Some level of user interaction (loading the applet) is implied by the vector's AC:M rating, though the record does not state this explicitly.

Exploitation

CISA KEV does not list this CVE, but EPSS gives a 30-day exploitation probability of about 0.70 (99th percentile), indicating high predicted likelihood. No reference is tagged as an exploit, so public exploit code is not confirmed by this record.

What to do

  • Upgrade to a Java SE 7 release after Update 21, or to a later supported Java version, per the Oracle June 2013 CPU advisory.
  • If Java cannot be updated, disable the Java browser plug-in and Java Web Start, or remove Java from endpoints that do not need it.
  • Apply the corresponding OpenJDK, Red Hat, SUSE, Gentoo, Mageia and Mandriva updates where those distributions are in use.
  • Enforce browser and JVM settings that block unsigned or untrusted applets and require user confirmation before execution.
  • Restrict outbound network access from hosts running Java so a sandbox escape cannot easily reach attacker infrastructure.

Detection

  • Monitor for Java processes spawning unexpected child processes such as cmd.exe, powershell.exe or /bin/sh, which can indicate sandbox escape.
  • Alert on JVM crashes or unusual Serviceability/tracing-related log entries in Java application and browser plug-in logs.
  • Hunt for outbound connections from browser or Java processes to newly registered or low-reputation domains shortly after applet load.
  • Inventory endpoints still running Java SE 7 Update 21 or earlier and OpenJDK 7 builds predating the fix.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://advisories.mageia.org/MGASA-2013-0185.html
http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/160cde99bb1a
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html
http://marc.info/?l=bugtraq&m=137545505800971&w=2
http://rhn.redhat.com/errata/RHSA-2013-0963.html
http://rhn.redhat.com/errata/RHSA-2013-1060.html
http://secunia.com/advisories/54154
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www-01.ibm.com/support/docview.wss?uid=swg21642336
http://www.mandriva.com/security/advisories?name=MDVSA-2013:183
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html Vendor Advisory
http://www.us-cert.gov/ncas/alerts/TA13-169A US Government Resource
https://bugzilla.redhat.com/show_bug.cgi?id=975122
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17116
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19129
http://advisories.mageia.org/MGASA-2013-0185.html
http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/160cde99bb1a
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html
http://marc.info/?l=bugtraq&m=137545505800971&w=2
http://rhn.redhat.com/errata/RHSA-2013-0963.html
http://rhn.redhat.com/errata/RHSA-2013-1060.html
http://secunia.com/advisories/54154
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www-01.ibm.com/support/docview.wss?uid=swg21642336
http://www.mandriva.com/security/advisories?name=MDVSA-2013:183
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html Vendor Advisory
http://www.us-cert.gov/ncas/alerts/TA13-169A US Government Resource
https://bugzilla.redhat.com/show_bug.cgi?id=975122
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17116
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19129

Track CVE-2013-2460 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2013-2465Oracle Java SE JRE 2D sandbox bypass and code executionCVE-2013-2465 is an unspecified vulnerability in the 2D component of Oracle Java SE JRE (7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update…KEVEPSS 99%analysed9.8CVE-2013-0422Oracle Java 7 JMX/MBean and Reflection API sandbox bypass RCEOracle Java 7 before Update 11 contains two flaws: the public getMBeanInstantiator method in JmxMBeanServer exposes a private MBeanInstantiator that …KEVEPSS 97%analysed9.8CVE-2012-5076Oracle Java SE JRE JAX-WS sandbox bypassCVE-2012-5076 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE 7 Update 7 and earlier, related to JA…KEVEPSS 91%analysed9.8CVE-2012-4681Oracle Java SE 7 JRE SecurityManager bypass allows remote code executionThe Java Runtime Environment in Oracle Java SE 7 Update 6 and earlier fails to properly enforce SecurityManager restrictions. A crafted applet can us…KEVEPSS 99%analysed9.8CVE-2012-1723Oracle Java SE Hotspot Improper Access Control Enables Remote Code ExecutionCVE-2012-1723 is an unspecified vulnerability in the Hotspot component of Oracle Java SE (JRE) affecting Java SE 7 update 4 and earlier, 6 update 32 …KEVEPSS 94%analysed9.8CVE-2012-0507Oracle Java SE JRE AtomicReferenceArray type confusion sandbox bypassCVE-2012-0507 is an unspecified vulnerability in the Java Runtime Environment (JRE) Concurrency component affecting Java SE 7 Update 2 and earlier, 6…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2013-2460), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.