CVE
- Id
- 67832
- CVE No.
- CVE-2014-0423
- Status
- Candidate
- Description
- Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote authenticated users to affect confidentiality and availability via unknown vectors related to Beans. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability in DocumentHandler.java, related to Beans decoding.
- Phase
- Assigned (20131212)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 655165 | 67832 | CVE-2014-0423 | CONFIRM:http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html | View |
| 655166 | 67832 | CVE-2014-0423 | CONFIRM:http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/995b32f013f5 | View |
| 655167 | 67832 | CVE-2014-0423 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=1053066 | View |
| 655168 | 67832 | CVE-2014-0423 | CONFIRM:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777 | View |
| 655169 | 67832 | CVE-2014-0423 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21679287 | View |
| 655170 | 67832 | CVE-2014-0423 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21677388 | View |
| 655171 | 67832 | CVE-2014-0423 | HP:HPSBUX02972 | View |
| 655172 | 67832 | CVE-2014-0423 | URL:http://marc.info/?l=bugtraq&m=139402697611681&w=2 | View |
| 655173 | 67832 | CVE-2014-0423 | HP:HPSBUX02973 | View |
| 655174 | 67832 | CVE-2014-0423 | URL:http://marc.info/?l=bugtraq&m=139402749111889&w=2 | View |
| 655175 | 67832 | CVE-2014-0423 | HP:SSRT101454 | View |
| 655176 | 67832 | CVE-2014-0423 | URL:http://marc.info/?l=bugtraq&m=139402697611681&w=2 | View |
| 655177 | 67832 | CVE-2014-0423 | HP:SSRT101455 | View |
| 655178 | 67832 | CVE-2014-0423 | URL:http://marc.info/?l=bugtraq&m=139402749111889&w=2 | View |
| 655179 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0026 | View |
| 655180 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0026.html | View |
| 655181 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0027 | View |
| 655182 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0027.html | View |
| 655183 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0097 | View |
| 655184 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0097.html | View |
| 655185 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0136 | View |
| 655186 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0136.html | View |
| 655187 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0030 | View |
| 655188 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0030.html | View |
| 655189 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0134 | View |
| 655190 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0134.html | View |
| 655191 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0135 | View |
| 655192 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0135.html | View |
| 655193 | 67832 | CVE-2014-0423 | SUSE:openSUSE-SU-2014:0174 | View |
| 655194 | 67832 | CVE-2014-0423 | URL:http://lists.opensuse.org/opensuse-updates/2014-01/msg00105.html | View |
| 655195 | 67832 | CVE-2014-0423 | SUSE:SUSE-SU-2014:0246 | View |
| 655196 | 67832 | CVE-2014-0423 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00009.html | View |
| 655197 | 67832 | CVE-2014-0423 | SUSE:SUSE-SU-2014:0266 | View |
| 655198 | 67832 | CVE-2014-0423 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00012.html | View |
| 655199 | 67832 | CVE-2014-0423 | SUSE:openSUSE-SU-2014:0177 | View |
| 655200 | 67832 | CVE-2014-0423 | URL:http://lists.opensuse.org/opensuse-updates/2014-01/msg00107.html | View |
| 655201 | 67832 | CVE-2014-0423 | SUSE:openSUSE-SU-2014:0180 | View |
| 655202 | 67832 | CVE-2014-0423 | URL:http://lists.opensuse.org/opensuse-updates/2014-02/msg00000.html | View |
| 655203 | 67832 | CVE-2014-0423 | SUSE:SUSE-SU-2014:0451 | View |
| 655204 | 67832 | CVE-2014-0423 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00024.html | View |
| 655205 | 67832 | CVE-2014-0423 | UBUNTU:USN-2089-1 | View |
| 655206 | 67832 | CVE-2014-0423 | URL:http://www.ubuntu.com/usn/USN-2089-1 | View |
| 655207 | 67832 | CVE-2014-0423 | UBUNTU:USN-2124-1 | View |
| 655208 | 67832 | CVE-2014-0423 | URL:http://www.ubuntu.com/usn/USN-2124-1 | View |
| 655209 | 67832 | CVE-2014-0423 | BID:64758 | View |
| 655210 | 67832 | CVE-2014-0423 | URL:http://www.securityfocus.com/bid/64758 | View |
| 655211 | 67832 | CVE-2014-0423 | BID:64914 | View |
| 655212 | 67832 | CVE-2014-0423 | URL:http://www.securityfocus.com/bid/64914 | View |
| 655213 | 67832 | CVE-2014-0423 | SECTRACK:1029608 | View |
| 655214 | 67832 | CVE-2014-0423 | URL:http://www.securitytracker.com/id/1029608 | View |
| 655215 | 67832 | CVE-2014-0423 | SECUNIA:56432 | View |
| 655216 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/56432 | View |
| 655217 | 67832 | CVE-2014-0423 | SECUNIA:56485 | View |
| 655218 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/56485 | View |
| 655219 | 67832 | CVE-2014-0423 | SECUNIA:56486 | View |
| 655220 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/56486 | View |
| 655221 | 67832 | CVE-2014-0423 | SECUNIA:56487 | View |
| 655222 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/56487 | View |
| 655223 | 67832 | CVE-2014-0423 | SECUNIA:56535 | View |
| 655224 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/56535 | View |
| 655225 | 67832 | CVE-2014-0423 | SECUNIA:60568 | View |
| 655226 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/60568 | View |
| 655227 | 67832 | CVE-2014-0423 | SECUNIA:59283 | View |
| 655228 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/59283 | View |
| 655229 | 67832 | CVE-2014-0423 | XF:oracle-cpujan2014-cve20140423(90340) | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 12256 | JVNDB-2014-001131 | Oracle MySQL の MySQL Server における InnoDB に関する脆弱性 | Oracle MySQL の MySQL Server には、InnoDB に関する処理に不備があるため、可用性に影響のある脆弱性が存在します。 | CVE-2014-0431 | 67832 | 3.5 | http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-001131.html | View |