CVE-2014-4209: Medium severity Oracle JDK vulnerability
It was discovered that the protection of the SubjectDelegator class was insufficient. An untrusted Java application or applet could possibly use this flaw to disclose or modify data related to the class.
Other sources
Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality and integrity via vectors related to JMX.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4209?
CVE-2014-4209 is rated as having a medium severity due to its potential to allow data disclosure or modification by untrusted applications.
How do I fix CVE-2014-4209?
To fix CVE-2014-4209, update your Oracle Java SE or JRE to the latest version available from Oracle.
Which versions are affected by CVE-2014-4209?
CVE-2014-4209 affects Oracle JDK/JRE versions 1.5.0-update65, 1.6.0-update75, 1.7.0-update60, and 1.8.0-update5.
What kind of applications can exploit CVE-2014-4209?
CVE-2014-4209 can be exploited by untrusted Java applications or applets.
Are there any known exploits for CVE-2014-4209?
There are no specific known exploits publicly disclosed for CVE-2014-4209, but the vulnerability poses a risk for data security.