CVE-2014-4220: Medium severity Oracle JDK vulnerability
Oracle Java SE 7u65 and 8u11 fixes an unspecified vulnerability in the Deployment component (CVE-2014-4220). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:N/I:P/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html#AppendixJAVA
Other sources
Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-4208.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4220?
CVE-2014-4220 has a CVSSv2 score of 5.0, indicating medium severity.
How do I fix CVE-2014-4220?
To fix CVE-2014-4220, update your Oracle Java SE to version 7u65 or 8u11 or later.
What versions are affected by CVE-2014-4220?
CVE-2014-4220 affects Oracle JDK 1.7.0-update60 and 1.8.0-update5.
What component is involved in CVE-2014-4220?
CVE-2014-4220 involves an unspecified vulnerability in the Deployment component of Oracle Java.
Is user authentication required to exploit CVE-2014-4220?
No, CVE-2014-4220 does not require user authentication to exploit.