CVE-2014-8891: Critical severity ibm sdk vulnerability
IBM JDK updates 7R1 SR2-FP10, 7 SR8-FP10, 6R1 SR8-FP3, 6 SR16-FP3 and 5.0 SR16-FP9 correct an unspecified vulnerability identified using CVE-2014-8891. Upstream has rated this issue with CVSSv2 score of 6.8 (no vector provided).
http://www.ibm.com/developerworks/java/jdk/alerts/#IBMSecurityUpdateFebruary2015
Further details of the issue should be made available via the following link:
http://www.ibm.com/support/docview.wss?uid=swg21695747
Other sources
Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR8-FP3, 7 before SR8-FP10, and 7R1 before SR2-FP10 allows remote attackers to escape the Java sandbox and execute arbitrary code via unspecified vectors related to the security manager.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8891?
CVE-2014-8891 has been rated with a CVSSv2 score of 6.8, indicating a medium severity level.
How do I fix CVE-2014-8891?
To fix CVE-2014-8891, update the IBM SDK, Java Technology Edition to the latest version specified in the affected software list.
Which versions of IBM SDK, Java Technology Edition are affected by CVE-2014-8891?
CVE-2014-8891 affects various versions of IBM SDK ranging from 5.0 SR16-FP9 up to 7.1 SR2-FP10.
Are there any workarounds for CVE-2014-8891?
There are no specific workarounds mentioned for CVE-2014-8891; updating to a fixed version is recommended.
What type of vulnerability is CVE-2014-8891?
CVE-2014-8891 is an unspecified vulnerability in IBM Java SDK that could potentially lead to security risks.