First published: Wed Oct 15 2014(Updated: )
Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and JRockit R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Security.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
BEA JRockit | =r27.8.3 | |
BEA JRockit | =r28.3.3 | |
Oracle JDK 6 | =1.5.0-update_71 | |
Oracle JDK 6 | =1.6.0-update81 | |
Oracle JDK 6 | =1.7.0-update60 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update_71 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update_81 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update_67 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update60 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update_20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-6558 is moderately critical as it allows remote attackers to affect the integrity of affected systems.
To fix CVE-2014-6558, update to the latest version of Oracle Java or JRockit that addresses this vulnerability.
CVE-2014-6558 affects Oracle Java SE 5.0u71, 6u81, 7u67, 8u20, Java SE Embedded 7u60, and specific JRockit versions.
CVE-2014-6558 allows remote attackers to potentially compromise the integrity of applications running on affected systems.
While the best mitigation for CVE-2014-6558 is updating the software, disabling the vulnerable Java components may act as a temporary workaround.