Oracle Java SE Multiple Vulnerabilities (January 2014 CPU)

critical Nessus Plugin ID 71966

Synopsis

The remote Windows host contains a programming platform that is potentially affected by multiple vulnerabilities.

Description

The version of Oracle (formerly Sun) Java SE or Java for Business installed on the remote host is earlier than 7 Update 51, 6 Update 71, or 5 Update 61. It is, therefore, potentially affected by security issues in the following components :

- 2D
- Beans
- CORBA
- Deployment
- Hotspot
- Install
- JAAS
- JavaFX
- JAXP
- JNDI
- JSSE
- Libraries
- Networking
- Security
- Serviceability

Solution

Update to JDK / JRE 7 Update 51, 6 Update 71 or 5 Update 61 or later and, if necessary, remove any affected versions.

Note that an Extended Support contract with Oracle is needed to obtain JDK / JRE 5 Update 61 or later or 6 Update 71 or later.

See Also

https://www.zerodayinitiative.com/advisories/ZDI-14-013/

https://www.zerodayinitiative.com/advisories/ZDI-14-038/

http://www.nessus.org/u?924160cd

Plugin Details

Severity: Critical

ID: 71966

File Name: oracle_java_cpu_jan_2014.nasl

Version: 1.14

Type: local

Agent: windows

Family: Windows

Published: 1/15/2014

Updated: 12/19/2024

Configuration: Enable thorough checks

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.5

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2014-0428

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:oracle:jdk, cpe:/a:oracle:jre

Required KB Items: installed_sw/Java

Exploit Ease: No known exploits are available

Patch Publication Date: 1/14/2014

Vulnerability Publication Date: 1/14/2014

Reference Information

CVE: CVE-2013-5870, CVE-2013-5878, CVE-2013-5884, CVE-2013-5887, CVE-2013-5889, CVE-2013-5893, CVE-2013-5895, CVE-2013-5896, CVE-2013-5898, CVE-2013-5899, CVE-2013-5902, CVE-2013-5904, CVE-2013-5905, CVE-2013-5906, CVE-2013-5907, CVE-2013-5910, CVE-2014-0368, CVE-2014-0373, CVE-2014-0375, CVE-2014-0376, CVE-2014-0382, CVE-2014-0385, CVE-2014-0387, CVE-2014-0403, CVE-2014-0408, CVE-2014-0410, CVE-2014-0411, CVE-2014-0415, CVE-2014-0416, CVE-2014-0417, CVE-2014-0418, CVE-2014-0422, CVE-2014-0423, CVE-2014-0424, CVE-2014-0428

BID: 64894, 64907, 64914, 64918, 64921, 64922, 64930, 64932, 64935, 64937, 64875, 64882, 64899, 64912, 64915, 64916, 64919, 64920, 64924, 64926, 64927, 64928, 64931, 64933, 64863, 64910, 64917, 64929, 64906, 64923, 64890, 64934, 64903, 64936, 64901