[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-0423Date: (C)2014-01-16   (M)2023-12-28


Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote authenticated users to affect confidentiality and availability via unknown vectors related to Beans. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability in DocumentHandler.java, related to Beans decoding.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.5
Exploit Score: 8.0
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECTRACK-1029608
SECUNIA-56432
SECUNIA-56485
SECUNIA-56486
SECUNIA-56487
SECUNIA-56535
SECUNIA-59283
SECUNIA-60568
BID-64758
BID-64914
RHSA-2014:0026
RHSA-2014:0027
RHSA-2014:0030
RHSA-2014:0097
RHSA-2014:0134
RHSA-2014:0135
RHSA-2014:0136
RHSA-2014:0414
SSRT101454
SSRT101455
SUSE-SU-2014:0246
SUSE-SU-2014:0266
SUSE-SU-2014:0451
USN-2089-1
USN-2124-1
http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/995b32f013f5
http://www-01.ibm.com/support/docview.wss?uid=swg21677388
http://www-01.ibm.com/support/docview.wss?uid=swg21679287
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
https://bugzilla.redhat.com/show_bug.cgi?id=1053066
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777
openSUSE-SU-2014:0174
openSUSE-SU-2014:0177
openSUSE-SU-2014:0180
oracle-cpujan2014-cve20140423(90340)

CPE    2
cpe:/a:oracle:jrockit:r27.7.7
cpe:/a:oracle:jrockit:r28.2.9
OVAL    23
oval:org.secpod.oval:def:1600184
oval:org.secpod.oval:def:501180
oval:org.secpod.oval:def:1600048
oval:org.secpod.oval:def:505663
...

© SecPod Technologies