CVE-2014-6457Oracle JDK vulnerability

11 documents8 sources
Severity
4.0MEDIUMNVD
EPSS
10.6%
top 6.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 15
Latest updateMay 13

Description

Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3, and R28.3.3 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE.

CVSS vector

AV:N/AC:H/C:N/I:P/A:PExploitability: 4.9 | Impact: 4.9

Affected Packages3 packages

NVDoracle/jrockitr27.8.3, r28.3.3+1
NVDoracle/jdk4 versions+3
NVDoracle/jre4 versions+3

Patches

🔴Vulnerability Details

4
GHSA
GHSA-5m53-6w9m-xpwf: Unspecified vulnerability in Oracle Java SE 52022-05-13
OSV
openjdk-7 vulnerabilities2014-10-23
OSV
CVE-2014-6457: Unspecified vulnerability in Oracle Java SE 52014-10-15
CVEList
CVE-2014-6457: Unspecified vulnerability in Oracle Java SE 52014-10-15

📋Vendor Advisories

5
Ubuntu
OpenJDK 7 vulnerabilities2014-10-23
Ubuntu
OpenJDK 7 vulnerabilities2014-10-23
Ubuntu
OpenJDK 6 vulnerabilities2014-10-17
Red Hat
OpenJDK: Triple Handshake attack against TLS/SSL connections (JSSE, 8037066)2014-10-14
Debian
CVE-2014-6457: openjdk-8 - Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java S...2014

💬Community

1
Bugzilla
CVE-2014-6457 OpenJDK: Triple Handshake attack against TLS/SSL connections (JSSE, 8037066)2014-10-09
CVE-2014-6457 — Oracle JDK vulnerability | cvebase