CVE-2014-6591: Low severity oracle java se 7 vulnerability
Published Jan 21, 2015
·Updated
Unspecified vulnerability in the Java SE component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6585.
Affected Software
8 affected components
Oracle JDK=1.5.0-update75
Oracle JDK=1.6.0-update85
Oracle JDK=1.7.0-update72
Oracle JDK=1.8.0-update25
ORACLE JRE=1.5.0-update75
ORACLE JRE=1.6.0-update85
ORACLE JRE=1.7.0-update72
ORACLE JRE=1.8.0-update25
Remediation
Event History
Jan 21, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6591?
CVE-2014-6591 is considered a moderate severity vulnerability affecting the confidentiality of the Java SE component.
2
What versions are affected by CVE-2014-6591?
CVE-2014-6591 affects Oracle Java SE versions 5.0u75, 6u85, 7u72, and 8u25.
3
How do I fix CVE-2014-6591?
To fix CVE-2014-6591, update your Oracle Java SE or JRE to a version that is not affected.
4
Can CVE-2014-6591 be exploited remotely?
Yes, CVE-2014-6591 can be exploited by remote attackers to affect the confidentiality of the system.
5
Is CVE-2014-6591 related to any other vulnerabilities?
CVE-2014-6591 is a different vulnerability than CVE-2014-6585, which deals with other aspects of Java security.