Oracle JRockit R27 < R27.8.2 / R28 < R28.3.2 Multiple Vulnerabilities (April 2014 CPU)

Critical Nessus Plugin ID 73612

Synopsis

The remote Windows host contains a programming platform that is potentially affected by multiple vulnerabilities.

Description

The remote host has a version of Oracle JRockit that is reportedly affected by vulnerabilities in the following components :

- 2D
- AWT
- Javadoc
- JNDI
- Libraries
- Security

Solution

Upgrade to version R27.8.2 / R28.3.2 or later.

See Also

http://www.nessus.org/u?ef1fc2a6

Plugin Details

Severity: Critical

ID: 73612

File Name: oracle_jrockit_cpu_apr_2014.nasl

Version: 1.6

Type: local

Agent: windows

Family: Windows

Published: 2014/04/18

Updated: 2018/07/18

Dependencies: 69304

Risk Information

Risk Factor: Critical

CVSS v2.0

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:oracle:jrockit

Required KB Items: installed_sw/Oracle JRockit

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2014/04/15

Vulnerability Publication Date: 2013/12/19

Reference Information

CVE: CVE-2013-6954, CVE-2014-0429, CVE-2014-0453, CVE-2014-0457, CVE-2014-0460, CVE-2014-1876, CVE-2014-2398

BID: 64493, 65568, 66856, 66866, 66914, 66916, 66920