CVE-2014-0428

HIGH

Description

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.

References

http://hg.openjdk.java.net/jdk7u/jdk7u/corba/rev/0a879f00b698

http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00009.html

http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00012.html

http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00024.html

http://lists.opensuse.org/opensuse-updates/2014-01/msg00105.html

http://lists.opensuse.org/opensuse-updates/2014-01/msg00107.html

http://lists.opensuse.org/opensuse-updates/2014-02/msg00000.html

http://marc.info/?l=bugtraq&m=139402697611681&w=2

http://marc.info/?l=bugtraq&m=139402749111889&w=2

http://osvdb.org/101996

http://rhn.redhat.com/errata/RHSA-2014-0026.html

http://rhn.redhat.com/errata/RHSA-2014-0027.html

http://rhn.redhat.com/errata/RHSA-2014-0030.html

http://rhn.redhat.com/errata/RHSA-2014-0097.html

http://rhn.redhat.com/errata/RHSA-2014-0134.html

http://rhn.redhat.com/errata/RHSA-2014-0135.html

http://rhn.redhat.com/errata/RHSA-2014-0136.html

http://secunia.com/advisories/56432

http://secunia.com/advisories/56485

http://secunia.com/advisories/56486

http://secunia.com/advisories/56535

http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html

http://www.securityfocus.com/bid/64758

http://www.securityfocus.com/bid/64935

http://www.securitytracker.com/id/1029608

http://www.ubuntu.com/usn/USN-2089-1

http://www.ubuntu.com/usn/USN-2124-1

https://access.redhat.com/errata/RHSA-2014:0414

https://bugzilla.redhat.com/show_bug.cgi?id=1051519

https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777

Details

Source: MITRE

Published: 2014-01-15

Updated: 2020-09-08

Risk Information

CVSS v2.0

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (40 total)

IDNameProductFamilySeverity
86358F5 Networks BIG-IP : OpenJDK vulnerability (SOL17381)NessusF5 Networks Local Security Checks
critical
79039RHEL 5 / 6 : IBM Java Runtime in Satellite Server (RHSA-2014:0982)NessusRed Hat Local Security Checks
critical
79011RHEL 5 / 6 : java-1.6.0-sun (RHSA-2014:0414)NessusRed Hat Local Security Checks
critical
76900RHEL 7 : java-1.7.1-ibm (RHSA-2014:0705)NessusRed Hat Local Security Checks
critical
76871AIX Java Advisory : java_jan2014_advisory.ascNessusAIX Local Security Checks
critical
75414openSUSE Security Update : java-1_7_0-openjdk (openSUSE-SU-2014:0180-1)NessusSuSE Local Security Checks
critical
75413openSUSE Security Update : java-1_7_0-openjdk (openSUSE-SU-2014:0174-1)NessusSuSE Local Security Checks
critical
74284SuSE 11.3 Security Update : IBM Java 6 (SAT Patch Number 9256)NessusSuSE Local Security Checks
critical
74254SuSE 11.3 Security Update : IBM Java 7 (SAT Patch Number 9263)NessusSuSE Local Security Checks
critical
73970IBM Notes 8.0.x / 8.5.x / 9.0.x with IBM Java < 1.6 SR15 FP1 Multiple VulnerabilitiesNessusWindows
critical
73969IBM Domino 8.0.x / 8.5.x / 9.0.x with IBM Java < 1.6 SR15 FP1 Multiple Vulnerabilities (credentialed check)NessusWindows
critical
73968IBM Domino 9.x < 9.0.1 Fix Pack 1 Multiple Vulnerabilities (uncredentialed check)NessusMisc.
critical
73398Ubuntu 10.04 LTS / 12.04 LTS : openjdk-6 regression (USN-2124-2)NessusUbuntu Local Security Checks
critical
72740Ubuntu 10.04 LTS / 12.04 LTS : openjdk-6 vulnerabilities (USN-2124-1)NessusUbuntu Local Security Checks
critical
72681SuSE 11.3 Security Update : IBM Java 6 (SAT Patch Number 8896)NessusSuSE Local Security Checks
critical
72555SuSE 11.3 Security Update : IBM Java (SAT Patch Number 8878)NessusSuSE Local Security Checks
critical
72423SuSE 11.3 Security Update : openjdk (SAT Patch Number 8874)NessusSuSE Local Security Checks
critical
72321RHEL 5 / 6 : java-1.5.0-ibm (RHSA-2014:0136)NessusRed Hat Local Security Checks
critical
72320RHEL 5 / 6 : java-1.6.0-ibm (RHSA-2014:0135)NessusRed Hat Local Security Checks
critical
72319RHEL 5 / 6 : java-1.7.0-ibm (RHSA-2014:0134)NessusRed Hat Local Security Checks
critical
72301Amazon Linux AMI : java-1.6.0-openjdk (ALAS-2014-283)NessusAmazon Linux Local Security Checks
critical
72298Amazon Linux AMI : java-1.7.0-openjdk (ALAS-2014-280)NessusAmazon Linux Local Security Checks
critical
72162Scientific Linux Security Update : java-1.6.0-openjdk on SL5.x, SL6.x i386/x86_64 (20140127)NessusScientific Linux Local Security Checks
critical
72161RHEL 5 / 6 : java-1.6.0-openjdk (RHSA-2014:0097)NessusRed Hat Local Security Checks
critical
72160Oracle Linux 5 / 6 : java-1.6.0-openjdk (ELSA-2014-0097)NessusOracle Linux Local Security Checks
critical
72153CentOS 5 / 6 : java-1.6.0-openjdk (CESA-2014:0097)NessusCentOS Local Security Checks
critical
72139GLSA-201401-30 : Oracle JRE/JDK: Multiple vulnerabilities (ROBOT)NessusGentoo Local Security Checks
critical
72117Ubuntu 12.10 / 13.04 / 13.10 : openjdk-7 vulnerabilities (USN-2089-1)NessusUbuntu Local Security Checks
critical
72055Mandriva Linux Security Advisory : java-1.7.0-openjdk (MDVSA-2014:011)NessusMandriva Local Security Checks
critical
71989Scientific Linux Security Update : java-1.7.0-openjdk on SL6.x i386/x86_64 (20140115)NessusScientific Linux Local Security Checks
critical
71988Scientific Linux Security Update : java-1.7.0-openjdk on SL5.x i386/x86_64 (20140115)NessusScientific Linux Local Security Checks
critical
71987RHEL 5 / 6 : java-1.7.0-oracle (RHSA-2014:0030)NessusRed Hat Local Security Checks
critical
71985Oracle Linux 5 : java-1.7.0-openjdk (ELSA-2014-0027)NessusOracle Linux Local Security Checks
critical
71984Oracle Linux 6 : java-1.7.0-openjdk (ELSA-2014-0026)NessusOracle Linux Local Security Checks
critical
71979CentOS 5 : java-1.7.0-openjdk (CESA-2014:0027)NessusCentOS Local Security Checks
critical
71978CentOS 6 : java-1.7.0-openjdk (CESA-2014:0026)NessusCentOS Local Security Checks
critical
71967Oracle Java SE Multiple Vulnerabilities (January 2014 CPU) (Unix)NessusMisc.
critical
71966Oracle Java SE Multiple Vulnerabilities (January 2014 CPU)NessusWindows
critical
71963RHEL 5 : java-1.7.0-openjdk (RHSA-2014:0027)NessusRed Hat Local Security Checks
critical
71962RHEL 6 : java-1.7.0-openjdk (RHSA-2014:0026)NessusRed Hat Local Security Checks
critical