CVE-2013-2415: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and
lowvulnerability
security
Summary
CVE-2013-2415 is an unspecified vulnerability in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, that affects the JAX-WS (Java API for XML Web Services, a tool for building web services) component and may leak sensitive information. The vulnerability requires local access (an attacker already on your computer) to exploit and cannot be used through untrusted applets or Java Web Start applications.
Vulnerability Details
CVSS Score
2.1
EPSS (30-day exploit probability)
EPSS: 0.1%
Classification
Attack SophisticationModerate
Impact (CIA+S)
confidentiality
Original source: https://nvd.nist.gov/vuln/detail/CVE-2013-2415
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 35%