CVE-2014-0460

UnknownEPSS 4.32%

Last modified

CVE-2014-0460 is a vulnerability of currently unknown severity. Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI.. EPSS estimates a 4.32% chance of exploitation in the next 30 days.

Description

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI.

Metrics

EPSS Probability
4.32%

89.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
OracleJrockitr27.8.1—
OracleJrockitr28.3.1—
CanonicalUbuntu Linux10.04—
CanonicalUbuntu Linux12.04—
CanonicalUbuntu Linux12.10—
CanonicalUbuntu Linux13.10—
CanonicalUbuntu Linux14.04—
JuniperJunos Space< 15.1—
OracleJdk1.5.0Update61
OracleJdk1.6.0Update71
OracleJdk1.7.0Update51
OracleJdk1.8.0—
OracleJre1.5.0Update61
OracleJre1.6.0Update71
OracleJre1.7.0Update51
OracleJre1.8.0—
DebianDebian Linux6.0—
DebianDebian Linux7.0—
DebianDebian Linux8.0—

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-0460?
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI.
How severe is CVE-2014-0460?
Severity scoring for CVE-2014-0460 is pending analysis. The EPSS model estimates a 4.32% probability of exploitation in the next 30 days.
How do I fix CVE-2014-0460?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2014

Are you affected by CVE-2014-0460?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST