First published: Tue Jul 15 2014(Updated: )
It was discovered that the protection of the SubjectDelegator class was insufficient. An untrusted Java application or applet could possibly use this flaw to disclose or modify data related to the class.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Java SE 7 | =1.5.0-update65 | |
Oracle Java SE 7 | =1.6.0-update75 | |
Oracle Java SE 7 | =1.7.0-update60 | |
Oracle Java SE 7 | =1.8.0-update5 | |
Oracle JRE | =1.5.0-update65 | |
Oracle JRE | =1.6.0-update75 | |
Oracle JRE | =1.7.0-update60 | |
Oracle JRE | =1.8.0-update5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4209 is rated as having a medium severity due to its potential to allow data disclosure or modification by untrusted applications.
To fix CVE-2014-4209, update your Oracle Java SE or JRE to the latest version available from Oracle.
CVE-2014-4209 affects Oracle JDK/JRE versions 1.5.0-update65, 1.6.0-update75, 1.7.0-update60, and 1.8.0-update5.
CVE-2014-4209 can be exploited by untrusted Java applications or applets.
There are no specific known exploits publicly disclosed for CVE-2014-4209, but the vulnerability poses a risk for data security.