Summary
This host is installed with Oracle Java SE JRE and is prone to multiple unspecified vulnerabilities.
Impact
Successful exploitation will allow remote attackers to update, insert, or delete certain data, execute arbitrary code, conduct denial-of-service and disclose sensitive information.
Impact Level: System/Application.
Solution
Apply the patch from below link,
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
Insight
Multiple unspecified flaws exists,
- An error in the Security subcomponent related to the Elliptic Curve (EC) cryptography implementation.
- An error in the Serviceability subcomponent related to share/native/sun/management/GcInfoBuilder.c
- An error in the Libraries subcomponent related to share/classes/java/lang/invoke/MethodHandles.java
- An unspecified error related to the Deployment subcomponent.
- Two errors related to the Deployment subcomponent.
- A format string error in the Hotspot subcomponent within the EventMark constructor and destructor in share/vm/utilities/events.cpp
Affected
Oracle Java SE 7 update 60 and prior, and 8 update 5 and prior on Windows
Detection
Get the installed version of Oracle Java SE JRE with the help of detect NVT and check it is vulnerable or not.
References
- http://secunia.com/advisories/59501
- http://securitytracker.com/id?1030577
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.osvdb.com/109134
- http://www.osvdb.com/109137
- http://www.osvdb.com/109139
- http://www.osvdb.com/109140
- http://www.osvdb.com/109143
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2014-2490, CVE-2014-4208, CVE-2014-4220, CVE-2014-4221, CVE-2014-4264, CVE-2014-4266 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Air Multiple Vulnerabilities - November12 (Mac OS X)
- Adobe AIR Multiple Vulnerabilities-01 Sep14 (Mac OS X)
- Adobe AIR Multiple Vulnerabilities(APSB14-22)-(Windows)
- Adobe Flash Player Arbitrary Code Execution Vulnerability - 01 Feb14 (Linux)
- Adobe AIR Code Execution and DoS Vulnerabilities Nov13 (Mac OS X)