Oracle Java JRE CVE-2013-0169 Weak Encryption Vulnerability

description-logoDescription

Supported versions that are affected are 7 Update 13 and before, 6 Update 39 and before, 5.0 Update 39 and before and 1.4.2_41 and before. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Java Runtime Environment accessible data. Note: Applies to server deployments of JSSE. SSL/TLS Plaintext Recovery vulnerability also known as "Lucky Thirteen" vulnerability. See http://www.isg.rhul.ac.uk/tls/.

affected-products-logoAffected Applications

Java JRE

CVE References

CVE-2013-0169