CVE-2014-0461
published 2014-04-16CVE-2014-0461: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and…
PriorityP354critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.99%
92.5th percentile
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| ibm | forms_viewer | >= 4.0.0 < 4.0.0.3 | 4.0.0.3 |
| ibm | forms_viewer | >= 8.0.0 < 8.0.1.1 | 8.0.1.1 |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2014-05-01·CVSS 10.0
CVE-2014-0429 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,
CVE-2014-0456, CVE-2014-0457, CVE-2014-0458, CVE-2014-0461, CVE-2014-0462,
CVE-2014-2397, CVE-2014-2405, CVE-2014-2412, CVE-2014-2414, CVE-2014-2421,
CVE-2014-2423, CVE-2014-2427)
Two vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)
A vulnerability wa
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2014-04-30·CVSS 10.0
CVE-2014-0429 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,
CVE-2014-2421, CVE-2014-2423, CVE-2014-2427)
Two vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)
A v
Red Hat
OpenJDK: Better ScriptEngineManager ScriptEngine management (Libraries, 8036794)
vendor_redhat·2014-04-15·CVSS 9.3
CVE-2014-0461 [CRITICAL] OpenJDK: Better ScriptEngineManager ScriptEngine management (Libraries, 8036794)
OpenJDK: Better ScriptEngineManager ScriptEngine management (Libraries, 8036794)
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 7) - Not affected
VulDB
Oracle Java SE/Java SE Embedded 6u71/7u51/8 Library cross site scripting (Nessus ID 73654 / ID 185086)
vuldb·2026-05-11·CVSS 9.3
CVE-2014-0461 [CRITICAL] Oracle Java SE/Java SE Embedded 6u71/7u51/8 Library cross site scripting (Nessus ID 73654 / ID 185086)
A vulnerability labeled as very critical has been found in Oracle Java SE and Java SE Embedded 6u71/7u51/8. The impacted element is an unknown function of the component Library Handler. Such manipulation leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2014-0461. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
GHSA
GHSA-jhjq-483p-7vc6: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity
ghsa_unreviewed·2022-05-10
CVE-2014-0461 [HIGH] GHSA-jhjq-483p-7vc6: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
OSV
openjdk-7 vulnerabilities
osv·2014-04-30·CVSS 10.0
CVE-2014-0429 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,
CVE-2014-2421, CVE-2014-2423, CVE-2014-2427)
Two vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)
A vulnerability was discovered in the OpenJDK JRE related to availabi
OSV
CVE-2014-0461: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity
osv·2014-04-15·CVSS 9.3
CVE-2014-0461 [CRITICAL] CVE-2014-0461: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0461 OpenJDK: Better ScriptEngineManager ScriptEngine management (Libraries, 8036794)
bugzilla·2014-04-14·CVSS 9.3
CVE-2014-0461 [CRITICAL] CVE-2014-0461 OpenJDK: Better ScriptEngineManager ScriptEngine management (Libraries, 8036794)
CVE-2014-0461 OpenJDK: Better ScriptEngineManager ScriptEngine management (Libraries, 8036794)
It was discovered that the ScriptEngineManager did not properly manage
ScriptEngines. An untrusted Java application or applet could possibly
use this flaw to bypass Java sandbox restrictions.
Discussion:
Fixed now in Oracle Java SE 6u75, 7u55 and 8u5 via Oracle Critical Patch Update Advisory - April 2014.
Fixed in IcedTea6 1.13.3 and IcedTea7 2.4.7:
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2014-April/027214.html
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2014-April/027222.html
External References:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
---
This issue has been addressed in following products:
Red Hat Enterprise Linux
Bugzilla
CVE-2014-0164 mcollective: world readable client config
bugzilla·2014-04-03·CVSS 2.1
CVE-2014-0164 [LOW] CVE-2014-0164 mcollective: world readable client config
CVE-2014-0164 mcollective: world readable client config
Jeremy Choi of Red Hat discovered that mcollective-client config file client.cfg contains authentication data and defaults to world readable.
Discussion:
Acknowledgements:
This issue was discovered by Jeremy Choi of the Red Hat Quality Engineering Group.
---
This issue has been addressed in following products:
RHEL 6 Version of OpenShift Enterprise 2.0
Via RHSA-2014:0460 https://rhn.redhat.com/errata/RHSA-2014-0460.html
---
This issue has been addressed in following products:
RHEL 6 Version of OpenShift Enterprise 1.2
Via RHSA-2014:0461 https://rhn.redhat.com/errata/RHSA-2014-0461.html
http://marc.info/?l=bugtraq&m=140852886808946&w=2http://marc.info/?l=bugtraq&m=140852974709252&w=2http://rhn.redhat.com/errata/RHSA-2014-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0685.htmlhttp://secunia.com/advisories/58415http://secunia.com/advisories/58974http://secunia.com/advisories/59058http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21672080http://www-01.ibm.com/support/docview.wss?uid=swg21676746http://www.debian.org/security/2014/dsa-2912http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/bid/66902http://www.ubuntu.com/usn/USN-2187-1http://www.ubuntu.com/usn/USN-2191-1https://access.redhat.com/errata/RHSA-2014:0413https://access.redhat.com/errata/RHSA-2014:0414https://www.ibm.com/support/docview.wss?uid=swg21675973http://marc.info/?l=bugtraq&m=140852886808946&w=2http://marc.info/?l=bugtraq&m=140852974709252&w=2http://rhn.redhat.com/errata/RHSA-2014-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0685.htmlhttp://secunia.com/advisories/58415http://secunia.com/advisories/58974http://secunia.com/advisories/59058http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21672080http://www-01.ibm.com/support/docview.wss?uid=swg21676746http://www.debian.org/security/2014/dsa-2912http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/bid/66902http://www.ubuntu.com/usn/USN-2187-1http://www.ubuntu.com/usn/USN-2191-1https://access.redhat.com/errata/RHSA-2014:0413https://access.redhat.com/errata/RHSA-2014:0414https://www.ibm.com/support/docview.wss?uid=swg21675973
2014-04-16
Published