<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1687073.xsl"?>
<?xml-stylesheet type="text/css" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1686935.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Critical Patch Update Advisory - February 2013 - Beta Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Critical Patch Update Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>JavaCPUFeb2013Update</ID>
      </Identification>
      <Status>Final</Status>
      <Version>1.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2013-02-19T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2013-02-19T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2013-02-19T13:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1905890.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>Ben Murphy</Name>
         <Organization>TippingPoint's Zero Day Initiative</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Kenny Paterson</Name>
         <Organization>Royal Holloway, University of London</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Michael Schierl</Name>
         <Organization>Michael Schierl</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Nadhem AlFardan</Name>
         <Organization>Royal Holloway, University of London</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Tomasko Labuda</Name>
         <Organization>iSIGHT Partners Global Vulnerability Partnership</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Will Dormann</Name>
         <Organization>CERT/CC</Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle Java SE" Type="Product Family">
            <Branch Name="Sun Java" Type="Product Name">
               <Branch Name="1.4.2_41 and before" Type="Product Version">
                  <FullProductName ProductID="P-856V-1.4.2_41 and before">Sun Java Version 1.4.2_41 and before</FullProductName>
               </Branch>
               <Branch Name="5.0 Update 39 and before" Type="Product Version">
                  <FullProductName ProductID="P-856V-5.0 Update 39 and before">Sun Java Version 5.0 Update 39 and before</FullProductName>
               </Branch>
               <Branch Name="6 Update 39 and before" Type="Product Version">
                  <FullProductName ProductID="P-856V-6 Update 39 and before">Sun Java Version 6 Update 39 and before</FullProductName>
               </Branch>
               <Branch Name="7 Update 13 and before" Type="Product Version">
                  <FullProductName ProductID="P-856V-7 Update 13 and before">Sun Java Version 7 Update 13 and before</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-0169</Title>
      <Notes>
         <Note Audience="All" Ordinal="1" Title="Details" Type="Details">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: JSSE).  Supported versions that are affected are 7 Update 13 and before, 6 Update 39 and before, 5.0 Update 39 and before and  1.4.2_41 and before. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java Runtime Environment accessible data.   Note: Applies to server deployments of JSSE. SSL/TLS Plaintext Recovery vulnerability also known as "Lucky Thirteen" vulnerability.  See http://www.isg.rhul.ac.uk/tls/. CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-0169</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 13 and before</ProductID>
            <ProductID>P-856V-6 Update 39 and before</ProductID>
            <ProductID>P-856V-5.0 Update 39 and before</ProductID>
            <ProductID>P-856V-1.4.2_41 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUFeb2013Update</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html</URL>
            <ProductID>P-856V-7 Update 13 and before</ProductID>
            <ProductID>P-856V-6 Update 39 and before</ProductID>
            <ProductID>P-856V-5.0 Update 39 and before</ProductID>
            <ProductID>P-856V-1.4.2_41 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-1484</Title>
      <Notes>
         <Note Audience="All" Ordinal="2" Title="Details" Type="Details">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Libraries
).  Supported versions that are affected are 7 Update 13 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-1484</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 13 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUFeb2013Update</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html</URL>
            <ProductID>P-856V-7 Update 13 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-1485</Title>
      <Notes>
         <Note Audience="All" Ordinal="3" Title="Details" Type="Details">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are 7 Update 13 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java Runtime Environment accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-1485</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 13 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUFeb2013Update</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html</URL>
            <ProductID>P-856V-7 Update 13 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-1486</Title>
      <Notes>
         <Note Audience="All" Ordinal="4" Title="Details" Type="Details">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: JMX).  Supported versions that are affected are 7 Update 13 and before, 6 Update 39 and before and  5.0 Update 39 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-1486</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 13 and before</ProductID>
            <ProductID>P-856V-6 Update 39 and before</ProductID>
            <ProductID>P-856V-5.0 Update 39 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUFeb2013Update</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html</URL>
            <ProductID>P-856V-7 Update 13 and before</ProductID>
            <ProductID>P-856V-6 Update 39 and before</ProductID>
            <ProductID>P-856V-5.0 Update 39 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-1487</Title>
      <Notes>
         <Note Audience="All" Ordinal="5" Title="Details" Type="Details">Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are 7 Update 13 and before and  6 Update 39 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through untrusted Java Web Start applications and untrusted Java applets. (Untrusted Java Web Start applications and untrusted applets run in the Java sandbox with limited privileges.). CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-1487</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-7 Update 13 and before</ProductID>
            <ProductID>P-856V-6 Update 39 and before</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>JavaCPUFeb2013Update</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013update-1905892.html</URL>
            <ProductID>P-856V-7 Update 13 and before</ProductID>
            <ProductID>P-856V-6 Update 39 and before</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
