CVE-2014-0387: High severity Oracle JDK vulnerability
Oracle Java SE 6u71 and 7u51 fixes an unspecified vulnerability in the Deployment component (CVE-2014-0387). Upstream has CVSSv2 scored this issue as: 7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
Other sources
Unspecified vulnerability in Oracle Java SE 6u65 and Java SE 7u45, when running on Firefox, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.75-1jpp.3.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.75-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.51-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-ibm-1:1.7.0.6.1-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.15.1-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.51-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-ibm-1:1.7.0.6.1-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.15.1-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1:1.7.1.1.0-1jpp.2.el7_0 - Upgrade
Upgrade
Oracle Java SE 6to a version that resolves this vulnerability.Fixed in 6u71 - Upgrade
Upgrade
Oracle Java SE 7to a version that resolves this vulnerability.Fixed in 7u51 - Upgrade
Upgrade
Oracle Java SE 6to a version that resolves this vulnerability.Fixed in 6u65 - Upgrade
Upgrade
Oracle Java SE 7to a version that resolves this vulnerability.Fixed in 7u45
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2014-0387?
CVE-2014-0387 has a CVSSv2 score of 7.6, indicating it is of high severity.
How do I fix CVE-2014-0387?
To fix CVE-2014-0387, update to the affected Java packages as specified in the Red Hat security advisory.
What versions of Java are affected by CVE-2014-0387?
CVE-2014-0387 affects Oracle Java SE versions 6u71 and 7u51 and other related packages.
What component is vulnerable in CVE-2014-0387?
The vulnerability in CVE-2014-0387 is found in the Deployment component of Oracle Java.
Is there an alternative to Java to avoid CVE-2014-0387?
Consider using alternative programming languages or runtime environments that do not rely on Java.