[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-0411Date: (C)2014-01-16   (M)2023-12-28


Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.0
Exploit Score: 4.9
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: NONE
  
Reference:
OSVDB-102028
SECTRACK-1029608
SECUNIA-56432
SECUNIA-56485
SECUNIA-56486
SECUNIA-56487
SECUNIA-56535
SECUNIA-57809
SECUNIA-59037
SECUNIA-59071
SECUNIA-59082
SECUNIA-59194
SECUNIA-59235
SECUNIA-59251
SECUNIA-59254
SECUNIA-59283
SECUNIA-59324
SECUNIA-59339
SECUNIA-59665
SECUNIA-59704
SECUNIA-59705
SECUNIA-59872
SECUNIA-60005
SECUNIA-60498
SECUNIA-60833
SECUNIA-60835
SECUNIA-60836
BID-64758
BID-64918
RHSA-2014:0026
RHSA-2014:0027
RHSA-2014:0030
RHSA-2014:0097
RHSA-2014:0134
RHSA-2014:0135
RHSA-2014:0136
RHSA-2014:0414
SSRT101454
SSRT101455
SUSE-SU-2014:0246
SUSE-SU-2014:0266
SUSE-SU-2014:0451
USN-2089-1
USN-2124-1
http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/d533e96c7acc
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004656
http://www-01.ibm.com/support/docview.wss?uid=swg21669519
http://www-01.ibm.com/support/docview.wss?uid=swg21675938
http://www-01.ibm.com/support/docview.wss?uid=swg21676190
http://www-01.ibm.com/support/docview.wss?uid=swg21676373
http://www-01.ibm.com/support/docview.wss?uid=swg21676978
http://www-01.ibm.com/support/docview.wss?uid=swg21677388
http://www-01.ibm.com/support/docview.wss?uid=swg21680234
http://www-01.ibm.com/support/docview.wss?uid=swg21680387
http://www-01.ibm.com/support/docview.wss?uid=swg21682668
http://www-01.ibm.com/support/docview.wss?uid=swg21682669
http://www-01.ibm.com/support/docview.wss?uid=swg21682670
http://www-01.ibm.com/support/docview.wss?uid=swg21682671
http://www-01.ibm.com/support/docview.wss?uid=swg21682904
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096132
http://www.ibm.com/support/docview.wss?uid=ssg1S1004745
http://www.ibm.com/support/docview.wss?uid=swg21672078
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
https://bugzilla.redhat.com/show_bug.cgi?id=1053010
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777
https://www.ibm.com/support/docview.wss?uid=swg21675223
https://www.ibm.com/support/docview.wss?uid=swg21677913
openSUSE-SU-2014:0174
openSUSE-SU-2014:0177
openSUSE-SU-2014:0180
oracle-cpujan2014-cve20140411(90357)

CPE    2
cpe:/a:oracle:jrockit:r27.7.7
cpe:/a:oracle:jrockit:r28.2.9
OVAL    23
oval:org.secpod.oval:def:1600184
oval:org.secpod.oval:def:501180
oval:org.secpod.oval:def:1600048
oval:org.secpod.oval:def:505663
...

© SecPod Technologies