CVE-2014-6517: Medium severity oracle java se vulnerability
Published Oct 15, 2014
·Updated
Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and Jrockit R27.8.3 and R28.3.3 allows remote attackers to affect confidentiality via vectors related to JAXP.
Affected Software
8 affected components
ORACLE Jrockit=r27.8.3
ORACLE Jrockit=r28.3.3
Oracle JDK=1.6.0-update81
Oracle JDK=1.7.0-update60
ORACLE JRE=1.6.0-update_81
ORACLE JRE=1.7.0-update_67
ORACLE JRE=1.7.0-update60
ORACLE JRE=1.8.0-update_20
Remediation
Event History
Oct 15, 2014
CVE Published
via MITRE·10:03 PM
Data Sourced
via MITRE·10:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6517?
CVE-2014-6517 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2014-6517?
To remediate CVE-2014-6517, upgrade to the latest version of Oracle Java SE or apply relevant patches as specified by Oracle.
3
Which versions are affected by CVE-2014-6517?
CVE-2014-6517 affects Oracle Java SE 6u81, 7u67, 8u20, and specific JRockit versions.
4
What types of attacks can CVE-2014-6517 facilitate?
CVE-2014-6517 allows remote attackers to potentially compromise confidentiality by exploiting vulnerabilities related to JAXP.
5
Is CVE-2014-6517 present in Java SE Embedded?
Yes, CVE-2014-6517 also affects Java SE Embedded version 7u60.