Skip to main content
Mallory
Critical

Oracle Java CMM crafted raster parameters remote code execution

IdentifiersCVE-2013-1493CWE-787

CVE-2013-1493 is a vulnerability in the color management (CMM) functionality of the 2D component in Oracle Java SE / JRE. Affected versions include Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier. The flaw can be triggered by processing an image containing crafted raster parameters. Oracle’s description states that exploitation can lead to either an out-of-bounds read or memory corruption in the JVM. Because the vulnerable code is reachable through attacker-supplied image content, a remote attacker can deliver a malicious Java applet or JAR that causes the JVM to parse the malformed image data and corrupt memory, resulting in arbitrary code execution or a JVM crash. The vulnerability was exploited in the wild in February 2013 and was subsequently incorporated into multiple exploit kits.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can result in arbitrary code execution in the context of the Java process, allowing compromise of the victim system subject to the privileges of the running user and the Java security context bypass achieved by the exploit chain. At minimum, the flaw can also be used to cause a denial of service by crashing the JVM. Historical reporting in the provided content shows active in-the-wild exploitation delivering malware including 9002 RAT and Poison Ivy via malicious JAR files, demonstrating practical use for initial access and payload execution.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure by disabling or removing the Java browser plugin, preventing untrusted Java applets/JARs from executing, restricting Java content in browsers, and limiting access to untrusted websites that can serve malicious applets. Application control, browser hardening, network egress controls, and detection of exploit-kit style delivery chains can reduce risk. In enterprise products bundling affected Java runtimes, isolate or disable vulnerable components until the updated SDK is deployed.

Remediation

Patch, then assume compromise.

Upgrade Oracle Java to a fixed release newer than Java SE 7 Update 15, 6 Update 41, and 5.0 Update 40. For environments using vendor-bundled Java runtimes, apply the vendor’s updated SDK or product fix pack. The provided content specifically notes IBM WebSphere Application Server remediation through updated IBM SDK levels and interim fixes, including upgrade paths such as WebSphere 8.0.0.6+, 7.0.0.29+, 6.1.0.47+, and 8.5.5.0+ where applicable, or the corresponding interim fixes/APARs identified by IBM.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
OracleJdkapplication
OracleJreapplication
SunJdkapplication
SunJreapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence1

Every observed campaign linking this CVE to a named adversary.

Associated malware3

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.

Oracle Java CMM crafted raster parameters remote code execution (CVE-2013-1493) | Mallory