CVE-2013-0431
Executive Summary
CVE-2013-0431 is a remote code execution flaw in Oracle Java SE 7 (up to Update 11) and OpenJDK 7 that lets attackers bypass the Java security sandbox via JMX, enabling user‑assisted exploitation. The vulnerability is actively exploited in the wild (CISA KEV).
Authoritative CVE Metadata - CVSS Base Score: 3.7 (LOW) - Published: 2013-01-31T14:55:01.327 - Last Modified: 2026-10-02T14:55:14.407
[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2022-05-25)
Original Description: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.
"He who fears being conquered is sure of defeat."
— Napoleon Bonaparte