VulnerabilityModified
CVE-2013-0485
Unspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR13-FP16 has unknown impact and attack vectors related to Class Libraries.
HIGH 10.0EPSS 2.44%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR13-FP16 has unknown impact and attack vectors related to Class Libraries.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.44% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- ibm/java
- Source
- psirt@us.ibm.com
References
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00020.html
- http://www.ibm.com/developerworks/java/jdk/aix/142_64/fixes.html#SR13FP16
- http://www.ibm.com/developerworks/java/jdk/aix/j532/fixes.html#SR16FP1
- http://www.ibm.com/developerworks/java/jdk/aix/j664/Java6_64.fixes.html#SR13FP1
- http://www.ibm.com/developerworks/java/jdk/aix/j732/Java7.fixes.html#SR4FP1
- https://bugzilla.redhat.com/show_bug.cgi?id=950072
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00020.html
- http://www.ibm.com/developerworks/java/jdk/aix/142_64/fixes.html#SR13FP16
- http://www.ibm.com/developerworks/java/jdk/aix/j532/fixes.html#SR16FP1
- http://www.ibm.com/developerworks/java/jdk/aix/j664/Java6_64.fixes.html#SR13FP1
- http://www.ibm.com/developerworks/java/jdk/aix/j732/Java7.fixes.html#SR4FP1
- https://bugzilla.redhat.com/show_bug.cgi?id=950072
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.