Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.
http://hg.openjdk.java.net/jdk7u/jdk7u/corba/rev/0a879f00b698
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00024.html
http://lists.opensuse.org/opensuse-updates/2014-01/msg00105.html
http://lists.opensuse.org/opensuse-updates/2014-01/msg00107.html
http://lists.opensuse.org/opensuse-updates/2014-02/msg00000.html
http://marc.info/?l=bugtraq&m=139402697611681&w=2
http://marc.info/?l=bugtraq&m=139402749111889&w=2
http://rhn.redhat.com/errata/RHSA-2014-0026.html
http://rhn.redhat.com/errata/RHSA-2014-0027.html
http://rhn.redhat.com/errata/RHSA-2014-0030.html
http://rhn.redhat.com/errata/RHSA-2014-0097.html
http://rhn.redhat.com/errata/RHSA-2014-0134.html
http://rhn.redhat.com/errata/RHSA-2014-0135.html
http://rhn.redhat.com/errata/RHSA-2014-0136.html
http://secunia.com/advisories/56432
http://secunia.com/advisories/56485
http://secunia.com/advisories/56486
http://secunia.com/advisories/56535
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
http://www.securityfocus.com/bid/64758
http://www.securityfocus.com/bid/64935
http://www.securitytracker.com/id/1029608
http://www.ubuntu.com/usn/USN-2089-1
http://www.ubuntu.com/usn/USN-2124-1
https://access.redhat.com/errata/RHSA-2014:0414
https://bugzilla.redhat.com/show_bug.cgi?id=1051519
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777
Source: MITRE
Published: 2014-01-15
Updated: 2020-09-08
Type: NVD-CWE-noinfo
Base Score: 10
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
Impact Score: 10
Exploitability Score: 10
Severity: HIGH
OR
OR
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
86358 | F5 Networks BIG-IP : OpenJDK vulnerability (SOL17381) | Nessus | F5 Networks Local Security Checks | critical |
79039 | RHEL 5 / 6 : IBM Java Runtime in Satellite Server (RHSA-2014:0982) | Nessus | Red Hat Local Security Checks | critical |
79011 | RHEL 5 / 6 : java-1.6.0-sun (RHSA-2014:0414) | Nessus | Red Hat Local Security Checks | critical |
76900 | RHEL 7 : java-1.7.1-ibm (RHSA-2014:0705) | Nessus | Red Hat Local Security Checks | critical |
76871 | AIX Java Advisory : java_jan2014_advisory.asc | Nessus | AIX Local Security Checks | critical |
75414 | openSUSE Security Update : java-1_7_0-openjdk (openSUSE-SU-2014:0180-1) | Nessus | SuSE Local Security Checks | critical |
75413 | openSUSE Security Update : java-1_7_0-openjdk (openSUSE-SU-2014:0174-1) | Nessus | SuSE Local Security Checks | critical |
74284 | SuSE 11.3 Security Update : IBM Java 6 (SAT Patch Number 9256) | Nessus | SuSE Local Security Checks | critical |
74254 | SuSE 11.3 Security Update : IBM Java 7 (SAT Patch Number 9263) | Nessus | SuSE Local Security Checks | critical |
73970 | IBM Notes 8.0.x / 8.5.x / 9.0.x with IBM Java < 1.6 SR15 FP1 Multiple Vulnerabilities | Nessus | Windows | critical |
73969 | IBM Domino 8.0.x / 8.5.x / 9.0.x with IBM Java < 1.6 SR15 FP1 Multiple Vulnerabilities (credentialed check) | Nessus | Windows | critical |
73968 | IBM Domino 9.x < 9.0.1 Fix Pack 1 Multiple Vulnerabilities (uncredentialed check) | Nessus | Misc. | critical |
73398 | Ubuntu 10.04 LTS / 12.04 LTS : openjdk-6 regression (USN-2124-2) | Nessus | Ubuntu Local Security Checks | critical |
72740 | Ubuntu 10.04 LTS / 12.04 LTS : openjdk-6 vulnerabilities (USN-2124-1) | Nessus | Ubuntu Local Security Checks | critical |
72681 | SuSE 11.3 Security Update : IBM Java 6 (SAT Patch Number 8896) | Nessus | SuSE Local Security Checks | critical |
72555 | SuSE 11.3 Security Update : IBM Java (SAT Patch Number 8878) | Nessus | SuSE Local Security Checks | critical |
72423 | SuSE 11.3 Security Update : openjdk (SAT Patch Number 8874) | Nessus | SuSE Local Security Checks | critical |
72321 | RHEL 5 / 6 : java-1.5.0-ibm (RHSA-2014:0136) | Nessus | Red Hat Local Security Checks | critical |
72320 | RHEL 5 / 6 : java-1.6.0-ibm (RHSA-2014:0135) | Nessus | Red Hat Local Security Checks | critical |
72319 | RHEL 5 / 6 : java-1.7.0-ibm (RHSA-2014:0134) | Nessus | Red Hat Local Security Checks | critical |
72301 | Amazon Linux AMI : java-1.6.0-openjdk (ALAS-2014-283) | Nessus | Amazon Linux Local Security Checks | critical |
72298 | Amazon Linux AMI : java-1.7.0-openjdk (ALAS-2014-280) | Nessus | Amazon Linux Local Security Checks | critical |
72162 | Scientific Linux Security Update : java-1.6.0-openjdk on SL5.x, SL6.x i386/x86_64 (20140127) | Nessus | Scientific Linux Local Security Checks | critical |
72161 | RHEL 5 / 6 : java-1.6.0-openjdk (RHSA-2014:0097) | Nessus | Red Hat Local Security Checks | critical |
72160 | Oracle Linux 5 / 6 : java-1.6.0-openjdk (ELSA-2014-0097) | Nessus | Oracle Linux Local Security Checks | critical |
72153 | CentOS 5 / 6 : java-1.6.0-openjdk (CESA-2014:0097) | Nessus | CentOS Local Security Checks | critical |
72139 | GLSA-201401-30 : Oracle JRE/JDK: Multiple vulnerabilities (ROBOT) | Nessus | Gentoo Local Security Checks | critical |
72117 | Ubuntu 12.10 / 13.04 / 13.10 : openjdk-7 vulnerabilities (USN-2089-1) | Nessus | Ubuntu Local Security Checks | critical |
72055 | Mandriva Linux Security Advisory : java-1.7.0-openjdk (MDVSA-2014:011) | Nessus | Mandriva Local Security Checks | critical |
71989 | Scientific Linux Security Update : java-1.7.0-openjdk on SL6.x i386/x86_64 (20140115) | Nessus | Scientific Linux Local Security Checks | critical |
71988 | Scientific Linux Security Update : java-1.7.0-openjdk on SL5.x i386/x86_64 (20140115) | Nessus | Scientific Linux Local Security Checks | critical |
71987 | RHEL 5 / 6 : java-1.7.0-oracle (RHSA-2014:0030) | Nessus | Red Hat Local Security Checks | critical |
71985 | Oracle Linux 5 : java-1.7.0-openjdk (ELSA-2014-0027) | Nessus | Oracle Linux Local Security Checks | critical |
71984 | Oracle Linux 6 : java-1.7.0-openjdk (ELSA-2014-0026) | Nessus | Oracle Linux Local Security Checks | critical |
71979 | CentOS 5 : java-1.7.0-openjdk (CESA-2014:0027) | Nessus | CentOS Local Security Checks | critical |
71978 | CentOS 6 : java-1.7.0-openjdk (CESA-2014:0026) | Nessus | CentOS Local Security Checks | critical |
71967 | Oracle Java SE Multiple Vulnerabilities (January 2014 CPU) (Unix) | Nessus | Misc. | critical |
71966 | Oracle Java SE Multiple Vulnerabilities (January 2014 CPU) | Nessus | Windows | critical |
71963 | RHEL 5 : java-1.7.0-openjdk (RHSA-2014:0027) | Nessus | Red Hat Local Security Checks | critical |
71962 | RHEL 6 : java-1.7.0-openjdk (RHSA-2014:0026) | Nessus | Red Hat Local Security Checks | critical |