CVE-2014-6512Insufficient Verification of Data Authenticity in Oracle JDK

Severity
4.3MEDIUMNVD
OSV4.0
EPSS
4.2%
top 11.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 15
Latest updateMay 13

Description

Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Libraries.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

NVDoracle/jrockitr27.8.3, r28.3.3+1
NVDoracle/jdk4 versions+3
NVDoracle/jre4 versions+3

Patches

🔴Vulnerability Details

4
GHSA
GHSA-hrpq-wp36-q3q3: Unspecified vulnerability in Oracle Java SE 52022-05-13
OSV
openjdk-7 vulnerabilities2014-10-23
OSV
CVE-2014-6512: Unspecified vulnerability in Oracle Java SE 52014-10-15
CVEList
CVE-2014-6512: Unspecified vulnerability in Oracle Java SE 52014-10-15

💥Exploits & PoCs

1
Exploit-DB
FreiChat 9.6 - SQL Injection2015-07-13

📋Vendor Advisories

5
Ubuntu
OpenJDK 7 vulnerabilities2014-10-23
Ubuntu
OpenJDK 7 vulnerabilities2014-10-23
Ubuntu
OpenJDK 6 vulnerabilities2014-10-17
Red Hat
OpenJDK: DatagramSocket connected socket missing source check (Libraries, 8039509)2014-10-14
Debian
CVE-2014-6512: openjdk-8 - Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java S...2014

💬Community

1
Bugzilla
CVE-2014-6512 OpenJDK: DatagramSocket connected socket missing source check (Libraries, 8039509)2014-02-28
CVE-2014-6512 — Oracle JDK vulnerability | cvebase