Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Oracle Java SE JRE Multiple Unspecified Vulnerabilities-01 Oct 2014 (Windows)

Information

Severity

Severity

Medium

Family

Family

General

CVSSv2 Base

CVSSv2 Base

6.8

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

9 years ago

Modified

Modified

5 years ago

Summary

The host is installed with Oracle Java SE JRE and is prone to multiple unspecified vulnerabilities.

Insight

Insight

Multiple flaws exist due to, - An unspecified error in share/classes/javax/crypto/CipherInputStream.java script related to streaming of input cipher streams. - An error in share/classes/java/util/ResourceBundle.java script related to property processing and handling of names. - An error in the 'LogRecord::readObject' function in classes/java/util/logging/LogRecord.java related to handling of resource bundles. - An error related to the wrapping of datagram sockets in the DatagramSocket implementation. - An error in share/classes/java/util/logging/Logger.java related to missing permission checks of logger resources. - An error related to handling of server certificate changes during SSL/TLS renegotiation. - An error within the 2D subcomponent of the client deployment.

Affected Software

Affected Software

Oracle Java SE 5 update 71 and prior, 6 update 81 and prior, 7 update 67 and prior, and 8 update 20 and prior on Windows

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

Apply the patch from the referenced advisory.