CVE-2014-8892: High severity ibm sdk vulnerability
IBM JDK updates 7R1 SR2-FP10, 7 SR8-FP10, 6R1 SR8-FP3, 6 SR16-FP3 and 5.0 SR16-FP9 correct an unspecified vulnerability identified using CVE-2014-8892. Upstream has rated this issue with CVSSv2 score of 4.3 (no vector provided).
http://www.ibm.com/developerworks/java/jdk/alerts/#IBMSecurityUpdateFebruary2015
Further details of the issue should be made available via the following link:
http://www.ibm.com/support/docview.wss?uid=swg21695747
Other sources
Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR8-FP3, 7 before SR8-FP10, and 7R1 before SR2-FP10 allows remote attackers to bypass intended access permissions and obtain sensitive information via unspecified vectors related to the security manager.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8892?
CVE-2014-8892 has a CVSSv2 score of 4.3, indicating a moderate severity level.
What versions of IBM JDK are affected by CVE-2014-8892?
CVE-2014-8892 affects IBM JDK versions 5.0 SR16-FP9, 6.0 SR16-FP3, 6.1 SR8-FP3, 7.0 SR8-FP10, and 7.1 SR2-FP10.
What are the mitigation steps for CVE-2014-8892?
To mitigate CVE-2014-8892, upgrade your IBM JDK to the patched versions 5.0 SR16-FP10, 6.1 SR8-FP10, or later as per the respective release notes.
When was CVE-2014-8892 published?
CVE-2014-8892 was published in 2014.
Is a workaround available for CVE-2014-8892?
There are no specific workarounds documented for CVE-2014-8892; updating to a secure version is recommended.