Security readout for executives and security teams
This is an old Oracle Java Runtime vulnerability in the 2D component. The public record says a remote attacker could affect confidentiality, integrity, and availability, but does not disclose the vector. Business exposure is mainly legacy systems still running Java SE 7u21 or earlier, 6u45 or earlier, or 5.0u45 or earlier. Likely exposure is limited to legacy endpoints, servers, or vendor applications retaining the affected Java Runtime versions. Internet-facing risk cannot be confirmed from the provided sources because the attack vector is described only as unknown remote vectors related to 2D. Prioritize discovery and cleanup of legacy Java. The vulnerability is old, but unsupported Java versions create durable risk and often indicate broader patch governance gaps. Mitigation focus: Inventory Java Runtime and JDK versions across endpoints and servers.; Apply Oracle or platform vendor Java security updates from the referenced advisories.; Remove obsolete Java versions where no business dependency remains..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2013-2464 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- RHSA-2014:0414CVE reference · vendor-advisory, x_refsource_REDHAT
- oval:org.mitre.oval:def:19227CVE reference · vdb-entry, signature
- oval:org.mitre.oval:def:19708CVE reference · vdb-entry, signature
- oval:org.mitre.oval:def:16389CVE reference · vdb-entry, signature
- oval:org.mitre.oval:def:19390CVE reference · vdb-entry, signature
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
