Vulnerability Name: | CVE-2014-0418 (CCN-90344) |
Assigned: | 2013-12-12 |
Published: | 2014-01-14 |
Updated: | 2022-05-13 |
Summary: | Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, and CVE-2014-0424. |
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): High Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): Low |
|
CVSS v2 Severity: | 5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P) 3.8 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): High Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P) 3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): High Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 5.1 Medium (REDHAT CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P) 3.8 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): High Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial |
|
Vulnerability Type: | CWE-noinfo
|
Vulnerability Consequences: | Unknown |
References: | Source: MITRE Type: CNA CVE-2014-0418
Source: HP Type: Third Party Advisory SSRT101454
Source: HP Type: Third Party Advisory SSRT101455
Source: OSVDB Type: Broken Link 102012
Source: CCN Type: RHSA-2014-0030 Critical: java-1.7.0-oracle security update
Source: REDHAT Type: Third Party Advisory RHSA-2014:0030
Source: SECUNIA Type: Permissions Required 56485
Source: SECUNIA Type: Permissions Required 56535
Source: CCN Type: Oracle Web site Oracle Critical Patch Update Advisory - January 2014
Source: CONFIRM Type: Vendor Advisory http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
Source: BID Type: Third Party Advisory, VDB Entry 64758
Source: CCN Type: BID-64758 RETIRED: Oracle January 2014 Critical Patch Update Multiple Vulnerabilities
Source: BID Type: Third Party Advisory, VDB Entry 64917
Source: CCN Type: BID-64917 Oracle Java SE CVE-2014-0418 Remote Security Vulnerability
Source: SECTRACK Type: Third Party Advisory, VDB Entry 1029608
Source: REDHAT Type: UNKNOWN RHSA-2014:0414
Source: XF Type: UNKNOWN oracle-cpujan2014-cve20140418(90344)
Source: XF Type: UNKNOWN oracle-cpujan2014-cve20140418(90344)
Source: CONFIRM Type: Third Party Advisory https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777
|
Vulnerable Configuration: | Configuration 1: cpe:/o:redhat:enterprise_linux_desktop_supplementary:6.0:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_server_supplementary_aus:6.5:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_hpc_node_supplementary:6.0:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_server_supplementary_eus:6.5.z:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_server_supplementary:6.0:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_workstation_supplementary:6.0:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_server_supplementary:5.0:*:*:*:*:*:*:*OR cpe:/o:redhat:enterprise_linux_desktop_supplementary:5.0:*:*:*:*:*:*:* Configuration 2: cpe:/a:oracle:jdk:1.6.0:update65:*:*:*:*:*:*OR cpe:/a:oracle:jre:1.6.0:update65:*:*:*:*:*:* Configuration 3: cpe:/a:oracle:jre:1.7.0:update45:*:*:*:*:*:* Configuration 4: cpe:/a:hp:jdk:*:*:*:*:*:*:*:* (Version <= 7.0.08)OR cpe:/a:hp:jre:*:*:*:*:*:*:*:* (Version <= 7.0.08)AND cpe:/o:hp:hp-ux:b.11.31:*:*:*:*:*:*:*OR cpe:/o:hp:hp-ux:b.11.23:*:*:*:*:*:*:* Configuration RedHat 1: cpe:/a:redhat:rhel_extras_oracle_java:5:*:*:*:*:*:*:* Configuration RedHat 2: cpe:/a:redhat:rhel_extras_oracle_java:6:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:oracle:jdk:1.7.0:update45:*:*:*:*:*:*OR cpe:/a:oracle:jre:1.7.0:update45:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |
redhat enterprise linux desktop supplementary 6.0
redhat enterprise linux server supplementary aus 6.5
redhat enterprise linux hpc node supplementary 6.0
redhat enterprise linux server supplementary eus 6.5.z
redhat enterprise linux server supplementary 6.0
redhat enterprise linux workstation supplementary 6.0
redhat enterprise linux server supplementary 5.0
redhat enterprise linux desktop supplementary 5.0
oracle jdk 1.6.0 update65
oracle jre 1.6.0 update65
oracle jre 1.7.0 update45
hp jdk *
hp jre *
hp hp-ux b.11.31
hp hp-ux b.11.23
oracle jdk 1.7.0 update45
oracle jre 1.7.0 update45