CVE-2014-4208: Low severity Oracle JDK vulnerability
Oracle Java SE 7u65 and 8u11 fixes an unspecified vulnerability in the Deployment component (CVE-2014-4208). Upstream has CVSSv2 scored this issue as: 2.6/AV:N/AC:H/Au:N/C:N/I:P/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html#AppendixJAVA
Other sources
Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-4220.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4208?
CVE-2014-4208 has a CVSSv2 score of 2.6, indicating low severity.
How do I fix CVE-2014-4208?
To fix CVE-2014-4208, update Oracle Java SE to versions 7u65 or 8u11 or later.
What components are affected by CVE-2014-4208?
The vulnerability affects the Deployment component in Oracle Java SE.
What versions of Oracle software are impacted by CVE-2014-4208?
CVE-2014-4208 impacts Oracle JDK 1.7.0-update60 and 1.8.0-update5, as well as their corresponding JRE versions.
Can CVE-2014-4208 be exploited remotely?
Yes, CVE-2014-4208 can potentially be exploited remotely due to its nature.