CVE-2014-2428
published 2014-04-16CVE-2014-2428: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and…
PriorityP348high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
5.08%
91.4th percentile
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | forms_viewer | >= 4.0.0 < 4.0.0.3 | 4.0.0.3 |
| ibm | forms_viewer | >= 8.0.0 < 8.0.1.1 | 8.0.1.1 |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
vendor_redhat·2014-04-15·CVSS 7.6
CVE-2014-2428 [HIGH] JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
JDK: unspecified vulnerability fixed in 6u75, 7u55 and 8u5 (Deployment)
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.6.0-sun (Red Hat Enterprise Linux 7) - Not affected
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 7) - Not affected
VulDB
Oracle Java SE/Java SE Embedded 6u71/7u51/8 Deployment Remote Code Execution (Nessus ID 73570 / ID 122007)
vuldb·2026-05-11·CVSS 7.6
CVE-2014-2428 [HIGH] Oracle Java SE/Java SE Embedded 6u71/7u51/8 Deployment Remote Code Execution (Nessus ID 73570 / ID 122007)
A vulnerability described as critical has been identified in Oracle Java SE and Java SE Embedded 6u71/7u51/8. This impacts an unknown function of the component Deployment Handler. Executing a manipulation can lead to Remote Code Execution.
The identification of this vulnerability is CVE-2014-2428. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-xj88-q9xm-8q7v: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity
ghsa_unreviewed·2022-05-10
CVE-2014-2428 [HIGH] GHSA-xj88-q9xm-8q7v: Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=140852886808946&w=2http://marc.info/?l=bugtraq&m=140852974709252&w=2http://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21672080http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/bid/66870https://access.redhat.com/errata/RHSA-2014:0413https://access.redhat.com/errata/RHSA-2014:0414http://marc.info/?l=bugtraq&m=140852886808946&w=2http://marc.info/?l=bugtraq&m=140852974709252&w=2http://security.gentoo.org/glsa/glsa-201502-12.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21672080http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/bid/66870https://access.redhat.com/errata/RHSA-2014:0413https://access.redhat.com/errata/RHSA-2014:0414
2014-04-16
Published