CVE-2014-0423XML External Entity (XXE) Injection in Oracle JDK

7 documents6 sources
Severity
5.5MEDIUMNVD
EPSS
0.4%
top 42.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 15
Latest updateMay 13

Description

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote authenticated users to affect confidentiality and availability via unknown vectors related to Beans. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability in DocumentHandler.java, related to Beans decoding.

CVSS vector

AV:N/AC:L/C:P/I:N/A:PExploitability: 8.0 | Impact: 4.9

Affected Packages3 packages

NVDoracle/jrockitr27.7.7, r28.2.9+1
NVDoracle/jdk1.5.0, 1.6.0+1
NVDoracle/jre1.5.0, 1.6.0, 1.7.0+2

🔴Vulnerability Details

2
GHSA
GHSA-3pf2-g488-cwrg: Unspecified vulnerability in Oracle Java SE 52022-05-13
CVEList
CVE-2014-0423: Unspecified vulnerability in Oracle Java SE 52014-01-15

📋Vendor Advisories

3
Ubuntu
OpenJDK 6 vulnerabilities2014-02-27
Ubuntu
OpenJDK 7 vulnerabilities2014-01-23
Red Hat
OpenJDK: XXE issue in decoder (Beans, 8023245)2014-01-14

💬Community

1
Bugzilla
CVE-2014-0423 OpenJDK: XXE issue in decoder (Beans, 8023245)2014-01-14
CVE-2014-0423 — XML External Entity (XXE) Injection | cvebase