[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-0416Date: (C)2014-01-16   (M)2023-12-28


Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect integrity via vectors related to JAAS. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to how principals are set for the Subject class, which allows attackers to escape the sandbox using deserialization of a crafted Subject instance.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
OSVDB-102017
SECTRACK-1029608
SECUNIA-56432
SECUNIA-56485
SECUNIA-56486
SECUNIA-56535
SECUNIA-59235
SECUNIA-59283
SECUNIA-59307
SECUNIA-59339
SECUNIA-60568
BID-64758
BID-64937
RHSA-2014:0026
RHSA-2014:0027
RHSA-2014:0030
RHSA-2014:0097
RHSA-2014:0134
RHSA-2014:0135
RHSA-2014:0136
RHSA-2014:0414
SSRT101454
SSRT101455
SUSE-SU-2014:0246
SUSE-SU-2014:0266
SUSE-SU-2014:0451
USN-2089-1
USN-2124-1
http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/abe1cb2d27cb
http://www-01.ibm.com/support/docview.wss?uid=swg21676978
http://www-01.ibm.com/support/docview.wss?uid=swg21677294
http://www-01.ibm.com/support/docview.wss?uid=swg21677388
http://www-01.ibm.com/support/docview.wss?uid=swg21679287
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
https://bugzilla.redhat.com/show_bug.cgi?id=1051912
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777
openSUSE-SU-2014:0174
openSUSE-SU-2014:0177
openSUSE-SU-2014:0180
oracle-cpujan2014-cve20140416(90349)

OVAL    23
oval:org.secpod.oval:def:16630
oval:org.secpod.oval:def:1600184
oval:org.secpod.oval:def:501180
oval:org.secpod.oval:def:1600048
...

© SecPod Technologies