First published: Wed Jan 21 2015(Updated: )
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
BEA JRockit | =r27.8.4 | |
BEA JRockit | =r28.3.4 | |
Oracle JDK 6 | =1.5.0-update75 | |
Oracle JDK 6 | =1.6.0-update85 | |
Oracle JDK 6 | =1.7.0-update71 | |
Oracle JDK 6 | =1.7.0-update72 | |
Oracle JDK 6 | =1.8.0-update25 | |
Oracle JDK 6 | =1.8.0-update6 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update75 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update85 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update71 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update72 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update25 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6593 is considered a critical vulnerability that can impact both confidentiality and integrity.
To fix CVE-2014-6593, you should update your Java SE or JRockit installations to the latest version provided by Oracle.
CVE-2014-6593 affects Oracle Java SE versions 5.0u75, 6u85, 7u72, 8u25, as well as JRockit versions 27.8.4 and 28.3.4.
Yes, CVE-2014-6593 can be exploited by remote attackers, potentially allowing unauthorized access to sensitive data.
The potential impacts of CVE-2014-6593 include unauthorized access, data leaks, and manipulation of sensitive information.