CVE-2014-4223: Critical severity Oracle JDK vulnerability
It was discovered that the Libraries component did not properly handle method invocations with an exhausted rank. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Other sources
Unspecified vulnerability in Oracle Java SE 7u60 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-2483.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4223?
CVE-2014-4223 has a moderate severity rating due to its potential to allow untrusted Java applications to bypass security restrictions.
How do I fix CVE-2014-4223?
To fix CVE-2014-4223, update to the latest version of Oracle Java SE or JDK that addresses this vulnerability.
What versions are affected by CVE-2014-4223?
CVE-2014-4223 affects Oracle JDK and JRE version 1.7.0-update60.
Can CVE-2014-4223 be exploited remotely?
Yes, CVE-2014-4223 can potentially be exploited remotely by an attacker using an untrusted Java application.
What are the implications of CVE-2014-4223?
The implications of CVE-2014-4223 include the possibility of unauthorized access and execution of code due to bypassing sandbox restrictions.