CVE-2014-0448: High severity Oracle Java SE 7 vulnerability
Oracle Java SE 7u55 and 8u5 fixes an unspecified vulnerability in the Deployment component (CVE-2014-0448). Upstream has CVSSv2 scored this issue as: 7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Other sources
Unspecified vulnerability in Oracle Java SE 7u51 and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.55-1jpp.2.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.55-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-ibm-1:1.7.0.7.0-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-ibm-1:1.7.0.7.0-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1:1.7.1.1.0-1jpp.2.el7_0 - Upgrade
Upgrade
Oracle Java SE 7to a version that resolves this vulnerability.Fixed in 7u55 - Upgrade
Upgrade
Oracle Java SE 8to a version that resolves this vulnerability.Fixed in 8u5
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2014-0448?
CVE-2014-0448 has a CVSSv2 score of 7.6, indicating a high severity vulnerability.
How do I fix CVE-2014-0448?
To fix CVE-2014-0448, update to the latest version of the affected Java packages as specified in vendor advisories.
Which versions of Java are affected by CVE-2014-0448?
CVE-2014-0448 affects Oracle Java SE 7u55 and Oracle Java SE 8u5, among other versions.
What component is affected by CVE-2014-0448?
CVE-2014-0448 affects the Deployment component of Oracle Java.
Is CVE-2014-0448 exploitable remotely?
Yes, CVE-2014-0448 is considered to be exploitable remotely, which increases its risk.