PT-2014-1273 · Oracle+4 · Oracle Jdk+8
Published
2014-01-15
·
Updated
2022-05-13
·
CVE-2014-0415
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Java Development Kit (affected versions not specified)
Java Runtime Environment (affected versions not specified)
Oracle JDK (affected versions not specified)
Oracle JRE (affected versions not specified)
Description
The issue allows a remote attacker to compromise the confidentiality, integrity, and availability of data using the Deployment subcomponent. This can be achieved by exploiting a vulnerability in the Java Development Kit, Java Runtime Environment, Oracle JDK, or Oracle JRE. The vulnerability is related to the subcomponents of the program.
Recommendations
For Java Development Kit, update to a version that addresses the issue with the Deployment subcomponent.
For Java Runtime Environment, update to a version that addresses the issue with the Deployment subcomponent.
For Oracle JDK, update to a version that addresses the issue with the Deployment subcomponent.
For Oracle JRE, update to a version that addresses the issue with the Deployment subcomponent.
As a temporary workaround, consider disabling the Deployment subcomponent until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp-Ux
Ibm Aix
Java Development Kit
Java Platform
Java Runtime Environment
Oracle Jdk
Oracle Jre
Red Hat
Suse