Oracle Java SE Remote Vulnerabilities (CVE-2014-6456)
Release date:
Updated on:
Affected Systems:
Oracle Java SE 8u20
Oracle Java SE 7u67
Description:
Bugtraq id: 70522
CVE (CAN) ID: CVE-2014-6456
Java SE is short for Java platform standard edition based on JDK and JRE. It is used to develop and deploy Java applications on the desktop, server, and embedded devices and real-time environments.
Oracle Java SE has a remote security vulnerability in the implementation of Java SE components. This vulnerability can be exploited through multiple protocols, unauthenticated remote attackers can exploit this vulnerability to affect the confidentiality, integrity, and availability of affected components. Versions affected by this vulnerability include Java SE 7u67 and Java SE 8u20.
<* Source: Oracle
Link: http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
*>
Suggestion:
Vendor patch:
Oracle
------
Oracle has released a Security Bulletin (cpuoct2014-1972960) and patches for this:
Cpuoct2014-1972960: Oracle Critical Patch Update Advisory-October 2014
Link: http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
This article permanently updates the link address: