Vulnerability Name:

CVE-2014-0448 (CCN-92468)

Assigned:2013-12-12
Published:2014-04-15
Updated:2022-05-13
Summary:Unspecified vulnerability in Oracle Java SE 7u51 and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
CVSS v3 Severity:9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.6 High (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
5.1 Medium (REDHAT CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
3.8 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2014-0448

Source: HP
Type: Issue Tracking, Mailing List, Third Party Advisory
SSRT101667

Source: CCN
Type: RHSA-2014-0412
Critical: java-1.7.0-oracle security update

Source: CCN
Type: RHSA-2014-0486
Critical: java-1.7.0-ibm security update

Source: CCN
Type: RHSA-2014-0705
Critical: java-1.7.1-ibm security update

Source: GENTOO
Type: Third Party Advisory
GLSA-201502-12

Source: CONFIRM
Type: Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21672080

Source: CCN
Type: IBM Security Bulletin 1020184
Multiple vulnerabilities in the IBM SDK Java Technology for IBM i

Source: CCN
Type: IBM Security Bulletin 1672043
Multiple vulnerabilities in current releases of the IBM SDK, Java Technology Edition

Source: CCN
Type: IBM Security Bulletin 1672047
Multiple vulnerabilities in IBM WebSphere Real Time

Source: CCN
Type: IBM Security Bulletin 1672080
InfoSphere Streams is possibly affected by vulnerabilities in the IBM SDK, Java Technology Edition (CVE-2014-0453 and CVE-2014-0460)

Source: CCN
Type: IBM Security Bulletin 1673611
Multiple IBM SDK Java Technology Edition, Version 7 security vulnerabilities addressed in IBM Endpoint Manager for Remote Control

Source: CCN
Type: IBM Security Bulletin 1675205
ulnerability in IBM Tivoli System Automation for Integrated Operations Management (several CVEs).

Source: CCN
Type: IBM Security Bulletin 1677490
Multiple IBM SDK Java Technology Edition, Version 6 security vulnerabilities addressed in Tivoli Endpoint Manager for Remote Control

Source: CCN
Type: IBM Security Bulletin 1678048
IBM Tivoli Composite Application Manager for Transactions affected by multiple vulnerabilities in IBM JRE (Multiple CVEs)

Source: CCN
Type: IBM Security Bulletin 1678139
Vulnerabilities in Rational Functional Tester due to IBM SDK, Java Technology Edition Version 1.6 and IBM SDK, Java Technology Edition Version 1.7

Source: CCN
Type: IBM Security Bulletin 1678883
Tivoli Application Dependency Discovery Manager - Java Quarterly CPU - April 2014.

Source: CCN
Type: IBM Security Bulletin 1679187
Potential security vulnerabilities with JavaTM SDKs

Source: CCN
Type: IBM Security Bulletin 1681114
IBM Notes and Domino - Multiple vulnerabilities in IBM Java (Oracle April 2014 Critical Patch Update) and IBM HTTP Server for Domino (CVE-2014-0963)

Source: CCN
Type: IBM Security Bulletin 1685350
Tivoli Storage Productivity Center - Oracle CPU April 2014

Source: CCN
Type: IBM Security Bulletin 1687297
Security Bulletin: IBM Tivoli Monitoring clients affected by vulnerabilities in IBM SDK, Java Technology Edition

Source: CCN
Type: Oracle Web site
Oracle Critical Patch Update Advisory - April 2014

Source: CONFIRM
Type: Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html

Source: BID
Type: Third Party Advisory, VDB Entry
66904

Source: CCN
Type: BID-66904
Oracle Java SE CVE-2014-0448 Remote Security Vulnerability

Source: REDHAT
Type: Third Party Advisory
RHSA-2014:0413

Source: XF
Type: UNKNOWN
oracle-cpuapr2014-cve20140448(92468)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:jdk:1.7.0:update51:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.7.0:update51:*:*:*:*:*:*
  • OR cpe:/a:oracle:jdk:1.8.0:-:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.8.0:-:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:ibm:forms_viewer:*:*:*:*:*:*:*:* (Version >= 8.0.0 and < 8.0.1.1)
  • OR cpe:/a:ibm:forms_viewer:*:*:*:*:*:*:*:* (Version >= 4.0.0 and < 4.0.0.3)
  • AND
  • cpe:/o:microsoft:windows:-:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/a:redhat:rhel_extras_oracle_java:5:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:rhel_extras_oracle_java:6:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:jre:1.7.0:update51:*:*:*:*:*:*
  • OR cpe:/a:oracle:jdk:1.7.0:update51:*:*:*:*:*:*
  • OR cpe:/a:oracle:jre:1.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:jdk:1.8.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:maximo_asset_management:7.5:*:*:*:*:*:*:*
  • OR cpe:/a:tivoli_storage_productivity_center:5.1:-:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:infosphere_streams:3.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:infosphere_streams:3.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:maximo_asset_management:7.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:infosphere_streams:3.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:domino:8.5.3.6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:domino:9.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:domino:8.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:domino:9.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_endpoint_manager:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:i:6.1:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:i:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:ibm:i:7.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_storage_productivity_center:5.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_application_dependency_discovery_manager:7.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_application_dependency_discovery_manager:7.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_real_time:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:domino:8.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:domino:8.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:domino:8.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:domino:9.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_application_dependency_discovery_manager:7.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:tivoli_storage_productivity_center:5.2.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20140448
    V
    CVE-2014-0448
    2022-05-20
    oval:com.redhat.rhsa:def:20140413
    P
    RHSA-2014:0413: java-1.7.0-oracle security update (Critical)
    2017-12-15
    oval:org.mitre.oval:def:26466
    V
    HP-UX running Java6, Remote Unauthorized Access, Disclosure of Information, and Other Vulnerabilities
    2015-04-20
    oval:org.mitre.oval:def:25167
    P
    SUSE-SU-2014:0733-1 -- Security update for IBM Java 7
    2014-09-08
    oval:org.mitre.oval:def:25310
    P
    SUSE-SU-2014:0733-2 -- Security update for IBM Java 7
    2014-09-08
    oval:org.mitre.oval:def:24767
    P
    ELSA-2014:0486: java-1.7.0-ibm security update (Critical)
    2014-09-01
    oval:org.mitre.oval:def:24411
    P
    ELSA-2014:0412: java-1.7.0-oracle security update (Critical)
    2014-07-21
    oval:org.mitre.oval:def:24759
    P
    ELSA-2014:0413: java-1.7.0-oracle security update (Critical)
    2014-07-21
    oval:org.mitre.oval:def:23870
    P
    RHSA-2014:0486: java-1.7.0-ibm security update (Critical)
    2014-06-30
    oval:org.mitre.oval:def:24489
    P
    RHSA-2014:0412: java-1.7.0-oracle security update (Critical)
    2014-06-09
    oval:org.mitre.oval:def:24723
    P
    RHSA-2014:0413: java-1.7.0-oracle security update (Critical)
    2014-06-09
    oval:org.mitre.oval:def:24169
    V
    Unspecified vulnerability in Oracle Java SE 7u51 and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment
    2014-06-02
    oval:com.redhat.rhsa:def:20140486
    P
    RHSA-2014:0486: java-1.7.0-ibm security update (Critical)
    2014-05-13
    oval:com.redhat.rhsa:def:20140412
    P
    RHSA-2014:0412: java-1.7.0-oracle security update (Critical)
    2014-04-17
    oval:com.ubuntu.trusty:def:20140448000
    V
    CVE-2014-0448 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-04-15
    oval:com.ubuntu.precise:def:20140448000
    V
    CVE-2014-0448 on Ubuntu 12.04 LTS (precise) - medium.
    2014-04-15
    BACK
    oracle jdk 1.7.0 update51
    oracle jre 1.7.0 update51
    oracle jdk 1.8.0 -
    oracle jre 1.8.0 -
    ibm forms viewer *
    ibm forms viewer *
    microsoft windows -
    oracle jre 1.7.0 update51
    oracle jdk 1.7.0 update51
    oracle jre 1.8.0
    oracle jdk 1.8.0
    ibm maximo asset management 7.5
    tivoli_storage_productivity_center 5.1 -
    ibm infosphere streams 3.0.0
    ibm infosphere streams 3.1.0
    ibm maximo asset management 7.1.1
    ibm infosphere streams 3.2.0
    ibm domino 8.5.3.6
    ibm domino 9.0.1
    ibm domino 8.5.0
    ibm domino 9.0
    ibm tivoli endpoint manager 8.0
    ibm i 6.1
    ibm i 7.1
    ibm i 7.2
    ibm tivoli storage productivity center 5.2.1
    ibm tivoli application dependency discovery manager 7.2.1
    ibm tivoli application dependency discovery manager 7.2.2
    ibm websphere real time 3.0
    ibm domino 8.5.1
    ibm domino 8.5.2
    ibm domino 8.5.3
    ibm domino 9.0.1.1
    ibm tivoli application dependency discovery manager 7.1.2
    ibm tivoli storage productivity center 5.2.2