CVE-2014-0403: Medium severity ORACLE JRE vulnerability
Oracle Java SE 6u71 and 7u51 fixes an unspecified vulnerability in the Deployment component (CVE-2014-0403). Upstream has CVSSv2 scored this issue as: 5.8/AV:N/AC:M/Au:N/C:P/I:P/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
Other sources
Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5898 and CVE-2014-0375.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.75-1jpp.3.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.75-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.51-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-ibm-1:1.7.0.6.1-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.15.1-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.51-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-ibm-1:1.7.0.6.1-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.15.1-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1:1.7.1.1.0-1jpp.2.el7_0 - Upgrade
Upgrade
Oracle Java SE 6to a version that resolves this vulnerability.Fixed in 6u71 - Upgrade
Upgrade
Oracle Java SE 7to a version that resolves this vulnerability.Fixed in 7u51 - Upgrade
Upgrade
Oracle Java SE 6to a version that resolves this vulnerability.Fixed in 6u65 - Upgrade
Upgrade
Oracle Java SE 7to a version that resolves this vulnerability.Fixed in 7u45
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2014-0403?
CVE-2014-0403 has a CVSSv2 score of 5.8, indicating medium severity.
What software versions are affected by CVE-2014-0403?
CVE-2014-0403 affects various versions of Oracle Java SE 6 and 7, specifically earlier than the specified updates.
How do I fix CVE-2014-0403?
To fix CVE-2014-0403, update Java to the latest versions specified in remediation notes.
Is CVE-2014-0403 an exploit risk for users?
Yes, CVE-2014-0403 poses a risk as it affects Java's Deployment component and could be exploited remotely.
When was CVE-2014-0403 publicly disclosed?
CVE-2014-0403 was publicly disclosed as part of Oracle's January 2014 Critical Patch Update.