Vulnerability Name: CVE-2014-4227 (CCN-94588) Assigned: 2014-07-15 Published: 2014-07-15 Updated: 2022-05-13 Summary: Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment. CVSS v3 Severity: 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C )7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C )7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
6.8 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P )5.0 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2014-4227 Source: SUSE Type: UNKNOWNSUSE-SU-2015:0344 Source: SUSE Type: UNKNOWNSUSE-SU-2015:0392 Source: HP Type: UNKNOWNHPSBUX03092 Source: CCN Type: RHSA-2014-1033Critical: java-1.6.0-ibm security update Source: CCN Type: RHSA-2014-1041Critical: java-1.7.0-ibm security update Source: CCN Type: RHSA-2014-1042Critical: java-1.7.1-ibm security update Source: REDHAT Type: UNKNOWNRHSA-2015:0264 Source: FULLDISC Type: UNKNOWN20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities Source: SECUNIA Type: UNKNOWN59404 Source: SECUNIA Type: UNKNOWN59680 Source: SECUNIA Type: UNKNOWN59924 Source: SECUNIA Type: UNKNOWN59986 Source: SECUNIA Type: UNKNOWN59987 Source: SECUNIA Type: UNKNOWN60081 Source: SECUNIA Type: UNKNOWN60245 Source: SECUNIA Type: UNKNOWN60317 Source: SECUNIA Type: UNKNOWN60622 Source: SECUNIA Type: UNKNOWN60817 Source: SECUNIA Type: UNKNOWN61577 Source: SECUNIA Type: UNKNOWN61640 Source: GENTOO Type: UNKNOWNGLSA-201502-12 Source: CONFIRM Type: UNKNOWNhttp://www-01.ibm.com/support/docview.wss?uid=swg21680334 Source: CONFIRM Type: UNKNOWNhttp://www-01.ibm.com/support/docview.wss?uid=swg21686383 Source: CONFIRM Type: UNKNOWNhttp://www-01.ibm.com/support/docview.wss?uid=swg21686824 Source: CCN Type: IBM Security Bulletin 1691846Multiple vulnerabilities in IBM Java SDK affect IBM FileNet System Monitor/IBM Enterprise Content Management System Monitor (CVE-2014-3086, CVE-2014-4227, CVE-2014-4262, CVE-2014-4219, CVE-2014-4268, CVE-2014-4218, CVE-2014-4252, CVE-2 Source: CCN Type: IBM Security Bulletin 1020258Multiple vulnerabilities in the IBM SDK Java Technology for IBM i Source: CCN Type: IBM Security Bulletin 1680333Multiple vulnerabilities in current releases of the IBM WebSphere Real Time Source: CCN Type: IBM Security Bulletin 1680334Multiple vulnerabilities in current releases of the IBM SDK, Java Technology Edition Source: CCN Type: IBM Security Bulletin 1682038Multiple vulnerabilities in IBM Java SDK and IBM Java Runtime, affect IBM Endpoint Manager for Remote Control Source: CCN Type: IBM Security Bulletin 1682102Multiple vulnerabilities in IBM Java SDK and IBM Java Runtime, affect Tivoli Endpoint Manager for Remote Control Source: CCN Type: IBM Security Bulletin 1685312IBM Tivoli Composite Application Manager for Transactions affected by multiple vulnerabilities in IBM JRE (Multiple CVEs) Source: CCN Type: IBM Security Bulletin 1685333Multiple vulnerabilities in IBM Java SDK affect Asset and Service Management Source: CCN Type: IBM Security Bulletin 1685866Vulnerabilities in IBM Tivoli System Automation for Integrated Operations Management (Several CVE's) Source: CCN Type: IBM Security Bulletin 1686194 Multiple vulnerabilities in IBM Java Runtime affect IBM Tivoli Application Dependency Discovery Manager (TADDM) (CVE-2014-4227, CVE-2014-4262, CVE-2014-4219, CVE-2014-4209, CVE-2014-4220, CVE-2014-4268, CVE-2014-4218, CVE-2014-4252, C Source: CCN Type: IBM Security Bulletin 1686383CICS Transaction Gateway for Multiplatforms Source: CCN Type: IBM Security Bulletin 1686824IBM Notes and Domino - Multiple vulnerabilities in IBM Java (Oracle July 2014 Critical Patch Update) Source: CCN Type: IBM Security Bulletin 1687297Security Bulletin: IBM Tivoli Monitoring clients affected by vulnerabilities in IBM SDK, Java Technology Edition Source: CCN Type: IBM Security Bulletin 1688312Multiple vulnerabilities in IBM Java Runtime affect IBM Cognos Business Viewpoint (CVE-2014-3086, CVE-2014-4227, CVE-2014-4262, CVE-2014-4220, CVE-2014-4218, CVE-2014-4252, CVE-2014-4265, CVE-2014-4221, CVE-2014-4263, CVE-2014-4244) Source: CCN Type: IBM Security Bulletin 1688343IBM Smart Analytics System 5600 is affected by multiple vulnerabilities in the IBM SDK Java Technology Edition, Version 6 Source: CCN Type: Oracle Critical Patch Update Advisory - July 2014Oracle Critical Patch Update Advisory - July 2014 Source: CONFIRM Type: Vendor Advisoryhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html Source: BUGTRAQ Type: UNKNOWN20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities Source: BID Type: UNKNOWN68603 Source: CCN Type: BID-68603Oracle Java SE CVE-2014-4227 Remote Security Vulnerability Source: SECTRACK Type: UNKNOWN1030577 Source: CONFIRM Type: UNKNOWNhttp://www.vmware.com/security/advisories/VMSA-2014-0012.html Source: REDHAT Type: UNKNOWNRHSA-2014:0902 Source: REDHAT Type: UNKNOWNRHSA-2014:0908 Source: XF Type: UNKNOWNoracle-cpujul2014-cve20144227(94588) Source: XF Type: UNKNOWNoracle-cpujul2014-cve20144227(94588) Source: CCN Type: WhiteSource Vulnerability DatabaseCVE-2014-4227 Vulnerable Configuration: Configuration 1 :cpe:/a:oracle:jdk:1.8.0:update5:*:*:*:*:*:* OR cpe:/a:oracle:jdk:1.7.0:update60:*:*:*:*:*:* OR cpe:/a:oracle:jdk:1.6.0:update75:*:*:*:*:*:* OR cpe:/a:oracle:jre:1.6.0:update75:*:*:*:*:*:* OR cpe:/a:oracle:jre:1.8.0:update5:*:*:*:*:*:* OR cpe:/a:oracle:jre:1.7.0:update60:*:*:*:*:*:* Configuration RedHat 1 :cpe:/a:redhat:rhel_extras_oracle_java:5:*:*:*:*:*:*:* Configuration RedHat 2 :cpe:/a:redhat:rhel_extras_oracle_java:6:*:*:*:*:*:*:* Configuration RedHat 3 :cpe:/a:redhat:rhel_extras_oracle_java:7:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:oracle:jdk:1.8.0:update5:*:*:*:*:*:* OR cpe:/a:oracle:jre:1.8.0:update5:*:*:*:*:*:* OR cpe:/a:oracle:jre:1.7.0:update60:*:*:*:*:*:* OR cpe:/a:oracle:jdk:1.7.0:update60:*:*:*:*:*:* AND cpe:/a:ibm:sdk:5.0:*:*:*:java:*:*:* OR cpe:/a:ibm:sdk:6.0:*:*:*:java:*:*:* OR cpe:/a:ibm:cics_transaction_gateway:8.0:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux_server_supplementary:6:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux_workstation_supplementary:6:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux_desktop_supplementary:6:*:*:*:*:*:*:* OR cpe:/o:redhat:enterprise_linux_hpc_node_supplementary:6:*:*:*:*:*:*:* OR cpe:/a:ibm:maximo_asset_management:7.5:*:*:*:*:*:*:* OR cpe:/a:ibm:cics_transaction_gateway:8.1:*:*:*:*:*:*:* OR cpe:/a:ibm:cics_transaction_gateway:9.0:*:*:*:*:*:*:* OR cpe:/a:ibm:filenet_system_monitor:4.5.0:*:*:*:*:*:*:* OR cpe:/a:ibm:filenet_system_monitor:5.1:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_composite_application_manager:7.3:*:*:*:transactions:*:*:* OR cpe:/a:ibm:maximo_asset_management:7.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_composite_application_manager:7.4:*:*:*:transactions:*:*:* OR cpe:/a:ibm:cognos_business_viewpoint:10.1:*:*:*:*:*:*:* OR cpe:/a:ibm:cognos_business_viewpoint:10.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:domino:8.5.3.5:*:*:*:*:*:*:* OR cpe:/a:ibm:domino:8.5.3.6:*:*:*:*:*:*:* OR cpe:/a:ibm:domino:9.0.1:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_endpoint_manager:*:*:*:*:*:*:*:* OR cpe:/o:ibm:i:6.1:*:*:*:*:*:*:* OR cpe:/o:ibm:i:7.1:*:*:*:*:*:*:* OR cpe:/o:ibm:i:7.2:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_monitoring:6.2.2:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_monitoring:6.2.3:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_monitoring:6.3.0:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_monitoring:6.2.0:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_monitoring:6.2.1:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_application_dependency_discovery_manager:7.2:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_application_dependency_discovery_manager:7.2.1:*:*:*:*:*:*:* OR cpe:/a:ibm:tivoli_application_dependency_discovery_manager:7.2.2:*:*:*:*:*:*:* OR cpe:/a:ibm:cics_transaction_gateway:9.1:*:*:*:*:*:*:* OR cpe:/a:ibm:sdk:6.1:*:*:*:java:*:*:* OR cpe:/a:ibm:sdk:7.0:*:*:*:java:*:*:* OR cpe:/a:ibm:sdk:7.1:*:*:*:java:*:*:* Denotes that component is vulnerable Oval Definitions BACK
oracle jdk 1.8.0 update5
oracle jdk 1.7.0 update60
oracle jdk 1.6.0 update75
oracle jre 1.6.0 update75
oracle jre 1.8.0 update5
oracle jre 1.7.0 update60
oracle jdk 1.8.0 update5
oracle jre 1.8.0 update5
oracle jre 1.7.0 update60
oracle jdk 1.7.0 update60
ibm sdk 5.0
ibm sdk 6.0
ibm cics transaction gateway 8.0
redhat enterprise linux server supplementary 6
redhat enterprise linux workstation supplementary 6
redhat enterprise linux desktop supplementary 6
redhat enterprise linux hpc node supplementary 6
ibm maximo asset management 7.5
ibm cics transaction gateway 8.1
ibm cics transaction gateway 9.0
ibm filenet system monitor 4.5.0
ibm filenet system monitor 5.1
ibm tivoli composite application manager 7.3
ibm maximo asset management 7.1.1
ibm tivoli composite application manager 7.4
ibm cognos business viewpoint 10.1
ibm cognos business viewpoint 10.1.1
ibm domino 8.5.3.5
ibm domino 8.5.3.6
ibm domino 9.0.1
ibm tivoli endpoint manager *
ibm i 6.1
ibm i 7.1
ibm i 7.2
ibm tivoli monitoring 6.2.2
ibm tivoli monitoring 6.2.3
ibm tivoli monitoring 6.3.0
ibm tivoli monitoring 6.2.0
ibm tivoli monitoring 6.2.1
ibm tivoli application dependency discovery manager 7.2
ibm tivoli application dependency discovery manager 7.2.1
ibm tivoli application dependency discovery manager 7.2.2
ibm cics transaction gateway 9.1
ibm sdk 6.1
ibm sdk 7.0
ibm sdk 7.1