PT-2014-1236 · Oracle+6 · Jax-Ws+9

Published

2014-04-15

·

Updated

2024-06-15

·

CVE-2014-0452

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Java Development Kit (affected versions not specified) Java Runtime Environment (affected versions not specified)
Description The issue is related to a component of the Java platform, specifically the JAX-WS subcomponent. Exploitation of this issue allows a remote attacker to compromise the confidentiality, integrity, and availability of data.
Recommendations For Java Development Kit, update to a version that addresses the issue with the JAX-WS subcomponent. For Java Runtime Environment, update to a version that addresses the issue with the JAX-WS subcomponent. As a temporary workaround, consider disabling the use of the JAX-WS subcomponent until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2014-00439
BDU:2014-00440
CESA-2014_0406
CESA-2014_0408
CVE-2014-0452
DSA-2912-1
DSA-2923-1
HPSBUX03091
HPSBUX03092
MGASA-2014-0189
OPENSUSE-SU-2024:10534-1
RHSA-2014:0406
RHSA-2014:0407
RHSA-2014:0408
RHSA-2014:0412
RHSA-2014:0413
RHSA-2014:0414
RHSA-2014:0486
RHSA-2014:0508
RHSA-2014:0675
RHSA-2014:0685
RHSA-2014:0705
RHSA-2014:0982
RHSA-2014_0406
RHSA-2014_0407
RHSA-2014_0408
RHSA-2014_0412
RHSA-2014_0413
RHSA-2014_0414
RHSA-2014_0486
RHSA-2014_0508
RHSA-2014_0675
RHSA-2014_0685
RHSA-2014_0705
USN-2187-1
USN-2191-1

Affected Products

Centos
Hp-Ux
Ibm Aix
Jax-Ws
Java Development Kit
Java Platform
Java Runtime Environment
Red Hat
Suse
Ubuntu