PT-2014-1248 · Oracle+6 · Java Development Kit+10

Published

2014-04-15

·

Updated

2024-06-15

·

CVE-2014-0451

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Java SE versions 5.0u61, 6u71, 7u51, and 8 Java SE Embedded version 7u51
Description The issue is related to the AWT subcomponent of the Java Runtime Environment and Java Development Kit, allowing a remote attacker to compromise the confidentiality, integrity, and availability of data.
Recommendations For Java SE versions 5.0u61, 6u71, 7u51, and 8, consider disabling the AWT subcomponent as a temporary workaround until a patch is available. For Java SE Embedded version 7u51, restrict access to the AWT subcomponent to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2014-00463
BDU:2014-00464
CESA-2014_0406
CESA-2014_0408
CVE-2014-0451
DSA-2912-1
DSA-2923-1
HPSBUX03091
HPSBUX03092
MGASA-2014-0189
OPENSUSE-SU-2024:10534-1
RHSA-2014:0406
RHSA-2014:0407
RHSA-2014:0408
RHSA-2014:0412
RHSA-2014:0413
RHSA-2014:0414
RHSA-2014:0486
RHSA-2014:0508
RHSA-2014:0509
RHSA-2014:0675
RHSA-2014:0685
RHSA-2014:0705
RHSA-2014:0982
RHSA-2014_0406
RHSA-2014_0407
RHSA-2014_0408
RHSA-2014_0412
RHSA-2014_0413
RHSA-2014_0414
RHSA-2014_0486
RHSA-2014_0508
RHSA-2014_0509
RHSA-2014_0675
RHSA-2014_0685
RHSA-2014_0705
USN-2187-1
USN-2191-1

Affected Products

Centos
Hp-Ux
Ibm Aix
Java Development Kit
Java Platform
Java Runtime Environment
Java Se
Java Se Embedded
Red Hat
Suse
Ubuntu