Lucene search

K
cve[email protected]CVE-2014-8891
HistoryMar 06, 2015 - 11:59 p.m.

CVE-2014-8891

2015-03-0623:59:00
web.nvd.nist.gov
68
cve-2014-8891
unspecified vulnerability
ibm sdk
java virtual machine
remote attackers
arbitrary code
security manager

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

4.6 Medium

AI Score

Confidence

High

0.036 Low

EPSS

Percentile

91.7%

Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR8-FP3, 7 before SR8-FP10, and 7R1 before SR2-FP10 allows remote attackers to escape the Java sandbox and execute arbitrary code via unspecified vectors related to the security manager.

Affected configurations

NVD
Node
ibmjava_sdkRange5.0.0.05.0.16.8technology
OR
ibmjava_sdkRange6.0.0.06.0.16.3technology
OR
ibmjava_sdkRange6.1.0.06.1.8.2technology
OR
ibmjava_sdkRange7.0.0.07.0.8.10technology
OR
ibmjava_sdkRange7.1.0.07.1.2.10technology

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

4.6 Medium

AI Score

Confidence

High

0.036 Low

EPSS

Percentile

91.7%