First published: Wed Oct 15 2014(Updated: )
Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3, and R28.3.3 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
BEA JRockit | =r27.8.3 | |
BEA JRockit | =r28.3.3 | |
Oracle JDK 6 | =1.5.0-update_71 | |
Oracle JDK 6 | =1.6.0-update81 | |
Oracle JDK 6 | =1.7.0-update60 | |
Oracle JDK 6 | =1.7.0-update67 | |
Oracle JDK 6 | =1.8.0-update20 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update_71 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update_81 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update_67 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update60 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update_20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6457 is considered a critical vulnerability that impacts confidentiality and integrity.
To remediate CVE-2014-6457, update your Oracle Java SE and JRockit to the latest versions provided by Oracle.
CVE-2014-6457 affects Oracle Java SE versions 5.0u71, 6u81, 7u67, 8u20, and certain JRockit versions.
The vulnerability in CVE-2014-6457 may allow remote attackers to compromise the confidentiality and integrity of affected systems.
CVE-2014-6457 remains a risk for systems still using the vulnerable versions of Oracle Java SE and JRockit without updates.