PT-2014-1262 · Oracle+7 · Java Development Kit+11
Published
2014-04-15
·
Updated
2024-06-15
·
CVE-2014-0458
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Java Runtime Environment (affected versions not specified)
Java Development Kit (affected versions not specified)
Oracle JDK (affected versions not specified)
Oracle JRE (affected versions not specified)
Canonical Ubuntu Linux (affected versions not specified)
Debian Debian Linux (affected versions not specified)
Description
The issue is related to a vulnerability in the Java platform, specifically affecting subcomponents of the program, including the JAX-WS subcomponent. This vulnerability can be exploited by a remote attacker to compromise the confidentiality, integrity, and availability of data. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations
For Java Runtime Environment, update to a version that includes the fix for this issue.
For Java Development Kit, update to a version that includes the fix for this issue.
For Oracle JDK, update to a version that includes the fix for this issue.
For Oracle JRE, update to a version that includes the fix for this issue.
For Canonical Ubuntu Linux, update to a version that includes the fix for this issue.
For Debian Debian Linux, update to a version that includes the fix for this issue.
As a temporary workaround, consider disabling the use of the JAX-WS subcomponent until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Debian
Hp-Ux
Ibm Aix
Java Development Kit
Java Platform
Java Runtime Environment
Oracle Jdk
Oracle Jre
Red Hat
Suse
Ubuntu