Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:JAVA:JMX-FINDCLASS-RCE

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Oracle Java JMX findClass and elementFromComplex Remote Code Execution

Release Date

2013/03/04

Update Number

2240

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Oracle Java JMX findClass and elementFromComplex Remote Code Execution


This signature detects attempts to exploit a known flaw in Oracle Java JMX classes. A successful exploit may result in remote code execution.

Extended Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.

Affected Products

  • oracle jdk 1.7.0 (update1)
  • oracle jdk 1.7.0 (update10)
  • oracle jdk 1.7.0 (update11)
  • oracle jdk 1.7.0 (update2)
  • oracle jdk 1.7.0 (update3)
  • oracle jdk 1.7.0 (update4)
  • oracle jdk 1.7.0 (update5)
  • oracle jdk 1.7.0 (update6)
  • oracle jdk 1.7.0 (update7)
  • oracle jdk 1.7.0 (update9)
  • oracle jre 1.7.0 (update1)
  • oracle jre 1.7.0 (update10)
  • oracle jre 1.7.0 (update11)
  • oracle jre 1.7.0 (update2)
  • oracle jre 1.7.0 (update3)
  • oracle jre 1.7.0 (update4)
  • oracle jre 1.7.0 (update5)
  • oracle jre 1.7.0 (update6)
  • oracle jre 1.7.0 (update7)
  • oracle jre 1.7.0 (update9)

References

  • BugTraq: 57726
  • CVE: CVE-2013-0431

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out