RHEL 7 : java-1.7.0-oracle (RHSA-2014:0902)

critical Nessus Plugin ID 79036

Synopsis

The remote Red Hat host is missing one or more security updates for java-1.7.0-oracle.

Description

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2014:0902 advisory.

Oracle Java SE version 7 includes the Oracle Java Runtime Environment and the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime Environment and the Oracle Java Software Development Kit. Further information about these flaws can be found on the Oracle Java SE Critical Patch Update Advisory page, listed in the References section.
(CVE-2014-4219, CVE-2014-2490, CVE-2014-4216, CVE-2014-4223, CVE-2014-4262, CVE-2014-2483, CVE-2014-4209, CVE-2014-4218, CVE-2014-4252, CVE-2014-4266, CVE-2014-4221, CVE-2014-4244, CVE-2014-4263, CVE-2014-4227, CVE-2014-4265, CVE-2014-4220, CVE-2014-4208, CVE-2014-4264)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat Product Security.

Note: The way in which the Oracle Java SE packages are delivered has changed. They now reside in a separate channel/repository that requires action from the user to perform prior to getting updated packages.
For information on subscribing to the new channel/repository please refer to: https://access.redhat.com/solutions/732883

All users of java-1.7.0-oracle are advised to upgrade to these updated packages, which provide Oracle Java 7 Update 65 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to take effect.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL java-1.7.0-oracle package based on the guidance in RHSA-2014:0902.

See Also

http://www.nessus.org/u?4743a1ef

http://www.nessus.org/u?a55403c9

https://access.redhat.com/solutions/732883

https://bugzilla.redhat.com/show_bug.cgi?id=1075795

https://bugzilla.redhat.com/show_bug.cgi?id=1119475

https://bugzilla.redhat.com/show_bug.cgi?id=1119476

https://bugzilla.redhat.com/show_bug.cgi?id=1119483

https://bugzilla.redhat.com/show_bug.cgi?id=1119596

https://bugzilla.redhat.com/show_bug.cgi?id=1119597

https://bugzilla.redhat.com/show_bug.cgi?id=1119600

https://bugzilla.redhat.com/show_bug.cgi?id=1119602

https://bugzilla.redhat.com/show_bug.cgi?id=1119608

https://bugzilla.redhat.com/show_bug.cgi?id=1119611

https://bugzilla.redhat.com/show_bug.cgi?id=1119613

https://bugzilla.redhat.com/show_bug.cgi?id=1119615

https://bugzilla.redhat.com/show_bug.cgi?id=1119622

https://bugzilla.redhat.com/show_bug.cgi?id=1119626

https://bugzilla.redhat.com/show_bug.cgi?id=1119912

https://bugzilla.redhat.com/show_bug.cgi?id=1119913

https://bugzilla.redhat.com/show_bug.cgi?id=1119914

https://bugzilla.redhat.com/show_bug.cgi?id=1119915

https://access.redhat.com/errata/RHSA-2014:0902

https://access.redhat.com/security/updates/classification/#critical

Plugin Details

Severity: Critical

ID: 79036

File Name: redhat-RHSA-2014-0902.nasl

Version: 1.19

Type: local

Agent: unix

Published: 11/8/2014

Updated: 3/20/2025

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2014-4227

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2014-4252

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:7, p-cpe:/a:redhat:enterprise_linux:java-1.7.0-oracle, p-cpe:/a:redhat:enterprise_linux:java-1.7.0-oracle-jdbc, p-cpe:/a:redhat:enterprise_linux:java-1.7.0-oracle-src, p-cpe:/a:redhat:enterprise_linux:java-1.7.0-oracle-devel, p-cpe:/a:redhat:enterprise_linux:java-1.7.0-oracle-plugin, p-cpe:/a:redhat:enterprise_linux:java-1.7.0-oracle-javafx

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 7/18/2014

Reference Information

CVE: CVE-2014-2483, CVE-2014-2490, CVE-2014-4208, CVE-2014-4209, CVE-2014-4216, CVE-2014-4218, CVE-2014-4219, CVE-2014-4220, CVE-2014-4221, CVE-2014-4223, CVE-2014-4227, CVE-2014-4244, CVE-2014-4252, CVE-2014-4262, CVE-2014-4263, CVE-2014-4264, CVE-2014-4265, CVE-2014-4266

CWE: 134

RHSA: 2014:0902