CVE-2014-0460
published 2014-04-16CVE-2014-0460: Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect…
PriorityP336medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
4.35%
90.2th percentile
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| juniper | junos_space | < 15.1 | 15.1 |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
| oracle | jrockit | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Java SE/JRockit/Java SE Embedded 5.0u61/6u71/7u51/8 JNDI cross site scripting (Nessus ID 73654 / ID 185086)
vuldb·2026-05-11·CVSS 5.8
CVE-2014-0460 [MEDIUM] Oracle Java SE/JRockit/Java SE Embedded 5.0u61/6u71/7u51/8 JNDI cross site scripting (Nessus ID 73654 / ID 185086)
A vulnerability marked as critical has been reported in Oracle Java SE, JRockit and Java SE Embedded 5.0u61/6u71/7u51/8. Affected by this vulnerability is an unknown functionality of the component JNDI. The manipulation leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2014-0460. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
GHSA-5fhm-4w6c-fp4v: Unspecified vulnerability in Oracle Java SE 5
ghsa_unreviewed·2022-05-10
CVE-2014-0460 [MEDIUM] GHSA-5fhm-4w6c-fp4v: Unspecified vulnerability in Oracle Java SE 5
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI.
OSV
openjdk-7 vulnerabilities
osv·2014-04-30·CVSS 10.0
CVE-2014-0429 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,
CVE-2014-2421, CVE-2014-2423, CVE-2014-2427)
Two vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)
A vulnerability was discovered in the OpenJDK JRE related to availabi
OSV
CVE-2014-0460: Unspecified vulnerability in Oracle Java SE 5
osv·2014-04-15·CVSS 5.8
CVE-2014-0460 [MEDIUM] CVE-2014-0460: Unspecified vulnerability in Oracle Java SE 5
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2014-05-01·CVSS 10.0
CVE-2014-0429 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,
CVE-2014-0456, CVE-2014-0457, CVE-2014-0458, CVE-2014-0461, CVE-2014-0462,
CVE-2014-2397, CVE-2014-2405, CVE-2014-2412, CVE-2014-2414, CVE-2014-2421,
CVE-2014-2423, CVE-2014-2427)
Two vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)
A vulnerability wa
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2014-04-30·CVSS 10.0
CVE-2014-0429 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,
CVE-2014-2421, CVE-2014-2423, CVE-2014-2427)
Two vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)
A v
Red Hat
OpenJDK: missing randomization of JNDI DNS client query IDs (JNDI, 8030731)
vendor_redhat·2014-04-15·CVSS 5.8
CVE-2014-0460 [MEDIUM] OpenJDK: missing randomization of JNDI DNS client query IDs (JNDI, 8030731)
OpenJDK: missing randomization of JNDI DNS client query IDs (JNDI, 8030731)
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI.
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0460 OpenJDK: missing randomization of JNDI DNS client query IDs (JNDI, 8030731)
bugzilla·2014-04-14·CVSS 5.8
CVE-2014-0460 [MEDIUM] CVE-2014-0460 OpenJDK: missing randomization of JNDI DNS client query IDs (JNDI, 8030731)
CVE-2014-0460 OpenJDK: missing randomization of JNDI DNS client query IDs (JNDI, 8030731)
It was discovered that the JNDI DNS client did not properly randomize
the DNS query ID. A remote attacker could exploit this flaw to e.g.
perfom DNS spoofing attacks.
Discussion:
Fixed now in Oracle Java SE 5.0u75, 6u75, 7u55 and 8u5 via Oracle Critical Patch Update Advisory - April 2014.
Fixed in IcedTea6 1.13.3 and IcedTea7 2.4.7:
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2014-April/027214.html
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2014-April/027222.html
External References:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2014:0407
Bugzilla
CVE-2014-0164 mcollective: world readable client config
bugzilla·2014-04-03·CVSS 2.1
CVE-2014-0164 [LOW] CVE-2014-0164 mcollective: world readable client config
CVE-2014-0164 mcollective: world readable client config
Jeremy Choi of Red Hat discovered that mcollective-client config file client.cfg contains authentication data and defaults to world readable.
Discussion:
Acknowledgements:
This issue was discovered by Jeremy Choi of the Red Hat Quality Engineering Group.
---
This issue has been addressed in following products:
RHEL 6 Version of OpenShift Enterprise 2.0
Via RHSA-2014:0460 https://rhn.redhat.com/errata/RHSA-2014-0460.html
---
This issue has been addressed in following products:
RHEL 6 Version of OpenShift Enterprise 1.2
Via RHSA-2014:0461 https://rhn.redhat.com/errata/RHSA-2014-0461.html
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698http://marc.info/?l=bugtraq&m=140852886808946&w=2http://marc.info/?l=bugtraq&m=140852974709252&w=2http://rhn.redhat.com/errata/RHSA-2014-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0685.htmlhttp://secunia.com/advisories/58415http://secunia.com/advisories/59022http://secunia.com/advisories/59023http://secunia.com/advisories/59058http://secunia.com/advisories/59071http://secunia.com/advisories/59082http://secunia.com/advisories/59250http://secunia.com/advisories/59255http://secunia.com/advisories/59307http://secunia.com/advisories/59436http://secunia.com/advisories/59516http://secunia.com/advisories/59642http://secunia.com/advisories/59704http://secunia.com/advisories/59705http://secunia.com/advisories/59706http://secunia.com/advisories/60003http://secunia.com/advisories/60111http://secunia.com/advisories/60117http://secunia.com/advisories/61264http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21672080http://www-01.ibm.com/support/docview.wss?uid=swg21673836http://www-01.ibm.com/support/docview.wss?uid=swg21674539http://www-01.ibm.com/support/docview.wss?uid=swg21676315http://www-01.ibm.com/support/docview.wss?uid=swg21676672http://www-01.ibm.com/support/docview.wss?uid=swg21676746http://www-01.ibm.com/support/docview.wss?uid=swg21677294http://www-01.ibm.com/support/docview.wss?uid=swg21679713http://www-01.ibm.com/support/docview.wss?uid=swg21681018http://www-01.ibm.com/support/docview.wss?uid=swg21681256http://www-01.ibm.com/support/docview.wss?uid=swg21683484http://www-01.ibm.com/support/docview.wss?uid=swg21686717http://www.debian.org/security/2014/dsa-2912http://www.ibm.com/support/docview.wss?uid=swg21675343http://www.ibm.com/support/docview.wss?uid=swg21675588http://www.ibm.com/support/docview.wss?uid=swg21677387http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/bid/66916http://www.ubuntu.com/usn/USN-2187-1http://www.ubuntu.com/usn/USN-2191-1https://access.redhat.com/errata/RHSA-2014:0413https://access.redhat.com/errata/RHSA-2014:0414http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698http://marc.info/?l=bugtraq&m=140852886808946&w=2http://marc.info/?l=bugtraq&m=140852974709252&w=2http://rhn.redhat.com/errata/RHSA-2014-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0685.htmlhttp://secunia.com/advisories/58415http://secunia.com/advisories/59022http://secunia.com/advisories/59023http://secunia.com/advisories/59058http://secunia.com/advisories/59071http://secunia.com/advisories/59082http://secunia.com/advisories/59250http://secunia.com/advisories/59255http://secunia.com/advisories/59307http://secunia.com/advisories/59436http://secunia.com/advisories/59516http://secunia.com/advisories/59642http://secunia.com/advisories/59704http://secunia.com/advisories/59705http://secunia.com/advisories/59706http://secunia.com/advisories/60003http://secunia.com/advisories/60111http://secunia.com/advisories/60117http://secunia.com/advisories/61264http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21672080http://www-01.ibm.com/support/docview.wss?uid=swg21673836http://www-01.ibm.com/support/docview.wss?uid=swg21674539http://www-01.ibm.com/support/docview.wss?uid=swg21676315http://www-01.ibm.com/support/docview.wss?uid=swg21676672http://www-01.ibm.com/support/docview.wss?uid=swg21676746http://www-01.ibm.com/support/docview.wss?uid=swg21677294http://www-01.ibm.com/support/docview.wss?uid=swg21679713http://www-01.ibm.com/support/docview.wss?uid=swg21681018http://www-01.ibm.com/support/docview.wss?uid=swg21681256http://www-01.ibm.com/support/docview.wss?uid=swg21683484http://www-01.ibm.com/support/docview.wss?uid=swg21686717http://www.debian.org/security/2014/dsa-2912http://www.ibm.com/support/docview.wss?uid=swg21675343http://www.ibm.com/support/docview.wss?uid=swg21675588http://www.ibm.com/support/docview.wss?uid=swg21677387http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/bid/66916http://www.ubuntu.com/usn/USN-2187-1http://www.ubuntu.com/usn/USN-2191-1https://access.redhat.com/errata/RHSA-2014:0413https://access.redhat.com/errata/RHSA-2014:0414
2014-04-16
Published