| Title | Oracle Java SE における Libraries に関する脆弱性 |
|---|---|
| Summary | Oracle Java SE には、Libraries に関する処理に不備があるため、機密性、完全性、および可用性に影響のある脆弱性が存在します。 本脆弱性は、CVE-2014-4223 とは異なる脆弱性です。 |
| Possible impacts | 第三者により、情報を取得される、情報を改ざんされる、およびサービス運用妨害 (DoS) 攻撃が行われる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | July 15, 2014, midnight |
| Registration Date | July 18, 2014, 12:29 p.m. |
| Last Update | March 18, 2015, 5:06 p.m. |
| CVSS2.0 : 危険 | |
| Score | 9.3 |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| オラクル |
| JDK 7 Update 60 |
| JRE 7 Update 60 |
| 日立 |
| Cosminexus Application Server Enterprise Version 6 |
| Cosminexus Application Server Standard Version 6 |
| Cosminexus Application Server Version 5 |
| Cosminexus Client Version 6 |
| Cosminexus Developer Light Version 6 |
| Cosminexus Developer Professional Version 6 |
| Cosminexus Developer Standard Version 6 |
| Cosminexus Developer Version 5 |
| Cosminexus Developer's Kit for Java(TM) |
| Cosminexus Primary Server Base |
| Cosminexus Studio Version 5 |
| uCosminexus Application Server -R |
| uCosminexus Application Server Express |
| uCosminexus Application Server Light |
| uCosminexus Application Server Standard-R |
| uCosminexus Application Server Enterprise |
| uCosminexus Application Server Smart Edition |
| uCosminexus Application Server Standard |
| uCosminexus Client |
| uCosminexus Client for Plug-in |
| uCosminexus Developer 01 |
| uCosminexus Developer Professional |
| uCosminexus Developer Professional for Plug-in |
| uCosminexus Developer Light |
| uCosminexus Developer Standard |
| uCosminexus Operator |
| uCosminexus Primary Server Base |
| uCosminexus Server Standard-R |
| uCosminexus Service Architect |
| uCosminexus Service Platform |
| uCosminexus Service Platform - Messaging |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2014年07月18日] 掲載 [2014年07月28日] 影響を受けるシステム:ベンダ情報の追加に伴い内容を更新 ベンダ情報:日立 (HS14-019) を追加 [2015年03月16日] 影響を受けるシステム:内容を更新 [2015年03月18日] 影響を受けるシステム:ベンダ情報の追加に伴い内容を更新 ベンダ情報:VMware (VMSA-2014-0012) を追加 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-4223. NOTE: the previous information is from the July 2014 CPU. Oracle has not commented on another vendor's claim that the issue is related to improper restriction of the "use of privileged annotations." |
|---|---|
| Publication Date | July 17, 2014, 2:10 p.m. |
| Registration Date | Jan. 26, 2021, 3:08 p.m. |
| Last Update | Nov. 21, 2024, 11:06 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:a:oracle:openjdk:1.7.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:jdk:1.7.0:update60:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:jre:1.7.0:update60:*:*:*:*:*:* | |||||