PT-2014-1272 · Oracle+5 · Oracle Java Se+7
Publicado
2014-01-15
·
Atualizado
2024-06-15
·
CVE-2014-0373
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Java SE versions 5.0u55, 6u65, and 7u45
OpenJDK 7
Description
The issue is related to the Serviceability component, allowing remote attackers to affect confidentiality, integrity, and availability. It is claimed that the problem may be related to the throwing of an incorrect exception when
SnmpStatusException should have been used in the SNMP implementation, potentially allowing attackers to escape the sandbox.Recommendations
For Oracle Java SE versions 5.0u55, 6u65, and 7u45, update to a version that is not affected by this issue.
For OpenJDK 7, consider disabling the Serviceability component as a temporary workaround until a patch is available.
Restrict access to the Serviceability component to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Hp-Ux
Ibm Aix
Java Platform
Openjdk
Oracle Java Se
Red Hat
Suse