PT-2014-1619 · Oracle+6 · Java Se+7

Published

2014-07-16

·

Updated

2024-06-15

·

CVE-2014-4209

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 5.0u65, 6u75, 7u60, and 8u5
Description The issue allows a remote attacker to compromise data confidentiality and integrity using the JMX subcomponent.
Recommendations For Oracle Java SE version 5.0u65, update to a version that is not affected by this issue. For Oracle Java SE version 6u75, update to a version that is not affected by this issue. For Oracle Java SE version 7u60, update to a version that is not affected by this issue. For Oracle Java SE version 8u5, update to a version that is not affected by this issue. As a temporary workaround, consider restricting access to the JMX subcomponent until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00537
BDU:2015-00582
CESA-2014_0889
CESA-2014_0907
CVE-2014-4209
DLA-96-1
DSA-2980-1
DSA-2987-1
HPSBUX03091
HPSBUX03092
MGASA-2014-0292
OPENSUSE-SU-2024:10534-1
RHSA-2014:0889
RHSA-2014:0890
RHSA-2014:0902
RHSA-2014:0907
RHSA-2014:0908
RHSA-2014:1033
RHSA-2014:1036
RHSA-2014:1041
RHSA-2014:1042
RHSA-2014_0889
RHSA-2014_0890
RHSA-2014_0902
RHSA-2014_0907
RHSA-2014_0908
RHSA-2014_1033
RHSA-2014_1036
RHSA-2014_1041
RHSA-2014_1042
RHSA-2015:0264
SUSE-SU-2014_1055-1
USN-2312-1
USN-2319-1
USN-2319-2
USN-2319-3

Affected Products

Centos
Hp-Ux
Ibm Aix
Java Platform
Java Se
Red Hat
Suse
Ubuntu