Oracle JRockit R27 < R27.8.2 / R28 < R28.3.2 Multiple Vulnerabilities (April 2014 CPU)

critical Nessus Plugin ID 73612

Synopsis

The remote Windows host contains a programming platform that is potentially affected by multiple vulnerabilities.

Description

The remote host has a version of Oracle JRockit that is reportedly affected by vulnerabilities in the following components :

- 2D
- AWT
- Javadoc
- JNDI
- Libraries
- Security

Solution

Upgrade to version R27.8.2 / R28.3.2 or later.

See Also

http://www.nessus.org/u?ef1fc2a6

Plugin Details

Severity: Critical

ID: 73612

File Name: oracle_jrockit_cpu_apr_2014.nasl

Version: 1.6

Type: local

Agent: windows

Family: Windows

Published: 4/18/2014

Updated: 7/18/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.5

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:oracle:jrockit

Required KB Items: installed_sw/Oracle JRockit

Exploit Ease: No known exploits are available

Patch Publication Date: 4/15/2014

Vulnerability Publication Date: 12/19/2013

Reference Information

CVE: CVE-2013-6954, CVE-2014-0429, CVE-2014-0453, CVE-2014-0457, CVE-2014-0460, CVE-2014-1876, CVE-2014-2398

BID: 64493, 65568, 66856, 66866, 66914, 66916, 66920