Description
This detection identifies exploitation attempts targeting CVE-2013-0422, which has a CRITICAL severity rating. Oracle Java 7 before Update 11 contains multiple vulnerabilities that let cyberattackers execute arbitrary code by obtaining a reference to a private MBeanInstantiator object through the public JmxMBeanServer class and by using the Reflection API in a way that bypasses a security check. Cyberattackers exploited the flaws in the wild in January 2013 through exploit kits such as Blackhole and Nuclear Pack.
Stats
- First seen
- July 2022
- Last seen
- October 2026
CVEs
Alert name variants
| Alert Name |
|---|
| Binary.Exploit.CVE-2013-0422 |
| ByteCode-JAVA.Exploit.CVE-2013-0422 |
| Java.Exploit.CVE-2013-0422.F |
| Java.Exploit.CVE-2013-0422.M |
| Java.Exploit.CVE-2013-0422.P |
| Package.Exploit.CVE-2013-0422 |
Related IPS Signatures
| Signature Name |
|---|
| EXPLOIT-KIT Redkit exploit kit redirection attempt |