CVE-2014-0890
published 2014-03-06CVE-2014-0890: The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.collaboration.realtime.telephony.*.level…
PriorityP46low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.34%
26.4th percentile
The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.collaboration.realtime.telephony.*.level setting is used, logs cleartext passwords during Audio/Video chat sessions, which allows local users to obtain sensitive information by reading a log file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4216 OpenJDK: Incorrect generic signature attribute parsing (Hotspot, 8037076)
bugzilla·2014-07-15·CVSS 9.3
CVE-2014-4216 [CRITICAL] CVE-2014-4216 OpenJDK: Incorrect generic signature attribute parsing (Hotspot, 8037076)
CVE-2014-4216 OpenJDK: Incorrect generic signature attribute parsing (Hotspot, 8037076)
It was discovered that the Hotspot component did not properly parse
invalid generic attributes for fields and methods. An untrusted Java
application or applet could possibly use this flaw to bypass Java
sandbox restrictions.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2014:0890 https://rhn.redhat.com/errata/RHSA-2014-0890.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2014:0889 https://rhn.redhat.com/errata/RHSA-2014-0889.html
---
Fixed now in Oracle Java SE 5u71, 6.0u81, 7.0u65, and 8.0u11
via Critical Patch Update July 2014.
Fixed in IcedTea 1.13.4 for Open
Bugzilla
CVE-2014-4223 OpenJDK: Incorrect handling of invocations with exhausted ranks (Libraries, 8035793)
bugzilla·2014-07-15·CVSS 9.3
CVE-2014-4223 [CRITICAL] CVE-2014-4223 OpenJDK: Incorrect handling of invocations with exhausted ranks (Libraries, 8035793)
CVE-2014-4223 OpenJDK: Incorrect handling of invocations with exhausted ranks (Libraries, 8035793)
It was discovered that the Libraries component did not properly
handle method invocations with an exhausted rank. An untrusted
Java application or applet could possibly use this flaw to bypass
Java sandbox restrictions.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2014:0890 https://rhn.redhat.com/errata/RHSA-2014-0890.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2014:0889 https://rhn.redhat.com/errata/RHSA-2014-0889.html
---
Fixed now in Oracle Java SE 7.0u65 via Critical Patch Update July 2014.
Fixed in IcedTea 2.5.1 for OpenJDK 7:
http://mail.op
Bugzilla
CVE-2014-2483 OpenJDK: Restrict use of privileged annotations (Libraries, 8034985)
bugzilla·2014-07-15·CVSS 9.3
CVE-2014-2483 [CRITICAL] CVE-2014-2483 OpenJDK: Restrict use of privileged annotations (Libraries, 8034985)
CVE-2014-2483 OpenJDK: Restrict use of privileged annotations (Libraries, 8034985)
It was discovered that the Libraries component did not properly
restrict the use of privileged annotations. An untrusted Java
application or applet could possibly use this flaw to bypass Java
sandbox restrictions.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2014:0890 https://rhn.redhat.com/errata/RHSA-2014-0890.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2014:0889 https://rhn.redhat.com/errata/RHSA-2014-0889.html
---
Fixed now in Oracle Java SE 7.0u65 via Critical Patch Update July 2014.
Fixed in IcedTea 2.5.1 for OpenJDK 7:
http://mail.openjdk.java.net/piperma
Bugzilla
CVE-2014-4219 OpenJDK: Bytecode verification does not prevent ctor calls to this() and super() (Hotspot, 8035119)
bugzilla·2014-07-15·CVSS 9.3
CVE-2014-4219 [CRITICAL] CVE-2014-4219 OpenJDK: Bytecode verification does not prevent ctor calls to this() and super() (Hotspot, 8035119)
CVE-2014-4219 OpenJDK: Bytecode verification does not prevent ctor calls to this() and super() (Hotspot, 8035119)
It was discovered that the bytecode verification did not properly
prevent ctor calls to this() and super() from certain code constructs.
An untrusted Java application or applet could possibly use this flaw to
bypass Java sandbox restrictions.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2014:0890 https://rhn.redhat.com/errata/RHSA-2014-0890.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2014:0889 https://rhn.redhat.com/errata/RHSA-2014-0889.html
---
Fixed now in Oracle Java SE 5u71, 6.0u81, 7.0u65, and 8.0u11
via Critical Patch Update
Bugzilla
CVE-2014-2490 OpenJDK: Event logger format string vulnerability (Hotspot, 8037076)
bugzilla·2014-07-15·CVSS 9.3
CVE-2014-2490 [CRITICAL] CVE-2014-2490 OpenJDK: Event logger format string vulnerability (Hotspot, 8037076)
CVE-2014-2490 OpenJDK: Event logger format string vulnerability (Hotspot, 8037076)
It was discovered that the event logger contains a format string
error. An untrusted Java application or applet could possibly use
this flaw to cause the Java Virtual Machine to crash, or, potentially,
execute arbitrary code with the privileges of the Java Virtual Machine.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2014:0890 https://rhn.redhat.com/errata/RHSA-2014-0890.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2014:0889 https://rhn.redhat.com/errata/RHSA-2014-0889.html
---
Fixed now in Oracle Java SE 5u71, 6.0u81, 7.0u65, and 8.0u11
via Critical Patch Update
Bugzilla
CVE-2014-4244 OpenJDK: RSA blinding issues (Security, 8031346)
bugzilla·2014-07-14·CVSS 4.0
CVE-2014-4244 [MEDIUM] CVE-2014-4244 OpenJDK: RSA blinding issues (Security, 8031346)
CVE-2014-4244 OpenJDK: RSA blinding issues (Security, 8031346)
It was discovered that the RSA algorithm in the OpenJDK Security component did not sufficiently preform "blinding" while performing operations using private keys. An attacker able to measure timing differences of those operations could possibly leak information about the keys used.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2014:0890 https://rhn.redhat.com/errata/RHSA-2014-0890.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2014:0889 https://rhn.redhat.com/errata/RHSA-2014-0889.html
---
Fixed now in Oracle Java SE 5u71, 6.0u81, 7.0u65, and 8.0u11
via Critical Patch Update July 2014.
Bugzilla
CVE-2014-4263 OpenJDK: insufficient Diffie-Hellman public key validation (Security, 8037162)
bugzilla·2014-07-14·CVSS 4.0
CVE-2014-4263 [MEDIUM] CVE-2014-4263 OpenJDK: insufficient Diffie-Hellman public key validation (Security, 8037162)
CVE-2014-4263 OpenJDK: insufficient Diffie-Hellman public key validation (Security, 8037162)
The Diffie-Hellman (DH) key exchange algorithm implementation in the OpenJDK Security component failed to validate public Diffie-Hellman parameters properly. This could allow OpenJDK implementation to accept and use weak parameters, making it possible for attackers to recover the negotiated key.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2014:0890 https://rhn.redhat.com/errata/RHSA-2014-0890.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2014:0889 https://rhn.redhat.com/errata/RHSA-2014-0889.html
---
Fixed now in Oracle Java SE 5u71, 6.0u81, 7.0u65, and
Bugzilla
CVE-2014-4221 OpenJDK: MethodHandles.Lookup insufficient modifiers checks (Libraries, 8035788)
bugzilla·2014-07-14·CVSS 4.3
CVE-2014-4221 [MEDIUM] CVE-2014-4221 OpenJDK: MethodHandles.Lookup insufficient modifiers checks (Libraries, 8035788)
CVE-2014-4221 OpenJDK: MethodHandles.Lookup insufficient modifiers checks (Libraries, 8035788)
It was discovered that MethodHandles.Lookup did not properly check for "protected" modifier, making it possible to access protected constructors in a different package. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2014:0890 https://rhn.redhat.com/errata/RHSA-2014-0890.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2014:0889 https://rhn.redhat.com/errata/RHSA-2014-0889.html
---
Fixed now in Oracle Java SE 7.0u65 and 8.0u11 via Critical Patch Update Jul
2014-03-06
Published