CVE
- Id
- 67832
- CVE No.
- CVE-2014-0423
- Status
- Candidate
- Description
- Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote authenticated users to affect confidentiality and availability via unknown vectors related to Beans. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability in DocumentHandler.java, related to Beans decoding.
- Phase
- Assigned (20131212)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
655165 | 67832 | CVE-2014-0423 | CONFIRM:http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html | View |
655166 | 67832 | CVE-2014-0423 | CONFIRM:http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/995b32f013f5 | View |
655167 | 67832 | CVE-2014-0423 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=1053066 | View |
655168 | 67832 | CVE-2014-0423 | CONFIRM:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777 | View |
655169 | 67832 | CVE-2014-0423 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21679287 | View |
655170 | 67832 | CVE-2014-0423 | CONFIRM:http://www-01.ibm.com/support/docview.wss?uid=swg21677388 | View |
655171 | 67832 | CVE-2014-0423 | HP:HPSBUX02972 | View |
655172 | 67832 | CVE-2014-0423 | URL:http://marc.info/?l=bugtraq&m=139402697611681&w=2 | View |
655173 | 67832 | CVE-2014-0423 | HP:HPSBUX02973 | View |
655174 | 67832 | CVE-2014-0423 | URL:http://marc.info/?l=bugtraq&m=139402749111889&w=2 | View |
655175 | 67832 | CVE-2014-0423 | HP:SSRT101454 | View |
655176 | 67832 | CVE-2014-0423 | URL:http://marc.info/?l=bugtraq&m=139402697611681&w=2 | View |
655177 | 67832 | CVE-2014-0423 | HP:SSRT101455 | View |
655178 | 67832 | CVE-2014-0423 | URL:http://marc.info/?l=bugtraq&m=139402749111889&w=2 | View |
655179 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0026 | View |
655180 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0026.html | View |
655181 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0027 | View |
655182 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0027.html | View |
655183 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0097 | View |
655184 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0097.html | View |
655185 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0136 | View |
655186 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0136.html | View |
655187 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0030 | View |
655188 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0030.html | View |
655189 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0134 | View |
655190 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0134.html | View |
655191 | 67832 | CVE-2014-0423 | REDHAT:RHSA-2014:0135 | View |
655192 | 67832 | CVE-2014-0423 | URL:http://rhn.redhat.com/errata/RHSA-2014-0135.html | View |
655193 | 67832 | CVE-2014-0423 | SUSE:openSUSE-SU-2014:0174 | View |
655194 | 67832 | CVE-2014-0423 | URL:http://lists.opensuse.org/opensuse-updates/2014-01/msg00105.html | View |
655195 | 67832 | CVE-2014-0423 | SUSE:SUSE-SU-2014:0246 | View |
655196 | 67832 | CVE-2014-0423 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00009.html | View |
655197 | 67832 | CVE-2014-0423 | SUSE:SUSE-SU-2014:0266 | View |
655198 | 67832 | CVE-2014-0423 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00012.html | View |
655199 | 67832 | CVE-2014-0423 | SUSE:openSUSE-SU-2014:0177 | View |
655200 | 67832 | CVE-2014-0423 | URL:http://lists.opensuse.org/opensuse-updates/2014-01/msg00107.html | View |
655201 | 67832 | CVE-2014-0423 | SUSE:openSUSE-SU-2014:0180 | View |
655202 | 67832 | CVE-2014-0423 | URL:http://lists.opensuse.org/opensuse-updates/2014-02/msg00000.html | View |
655203 | 67832 | CVE-2014-0423 | SUSE:SUSE-SU-2014:0451 | View |
655204 | 67832 | CVE-2014-0423 | URL:http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00024.html | View |
655205 | 67832 | CVE-2014-0423 | UBUNTU:USN-2089-1 | View |
655206 | 67832 | CVE-2014-0423 | URL:http://www.ubuntu.com/usn/USN-2089-1 | View |
655207 | 67832 | CVE-2014-0423 | UBUNTU:USN-2124-1 | View |
655208 | 67832 | CVE-2014-0423 | URL:http://www.ubuntu.com/usn/USN-2124-1 | View |
655209 | 67832 | CVE-2014-0423 | BID:64758 | View |
655210 | 67832 | CVE-2014-0423 | URL:http://www.securityfocus.com/bid/64758 | View |
655211 | 67832 | CVE-2014-0423 | BID:64914 | View |
655212 | 67832 | CVE-2014-0423 | URL:http://www.securityfocus.com/bid/64914 | View |
655213 | 67832 | CVE-2014-0423 | SECTRACK:1029608 | View |
655214 | 67832 | CVE-2014-0423 | URL:http://www.securitytracker.com/id/1029608 | View |
655215 | 67832 | CVE-2014-0423 | SECUNIA:56432 | View |
655216 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/56432 | View |
655217 | 67832 | CVE-2014-0423 | SECUNIA:56485 | View |
655218 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/56485 | View |
655219 | 67832 | CVE-2014-0423 | SECUNIA:56486 | View |
655220 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/56486 | View |
655221 | 67832 | CVE-2014-0423 | SECUNIA:56487 | View |
655222 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/56487 | View |
655223 | 67832 | CVE-2014-0423 | SECUNIA:56535 | View |
655224 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/56535 | View |
655225 | 67832 | CVE-2014-0423 | SECUNIA:60568 | View |
655226 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/60568 | View |
655227 | 67832 | CVE-2014-0423 | SECUNIA:59283 | View |
655228 | 67832 | CVE-2014-0423 | URL:http://secunia.com/advisories/59283 | View |
655229 | 67832 | CVE-2014-0423 | XF:oracle-cpujan2014-cve20140423(90340) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
12256 | JVNDB-2014-001131 | Oracle MySQL の MySQL Server における InnoDB に関する脆弱性 | Oracle MySQL の MySQL Server には、InnoDB に関する処理に不備があるため、可用性に影響のある脆弱性が存在します。 | CVE-2014-0431 | 67832 | 3.5 | http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-001131.html | View |