CVE-2014-6593

Oracle Java SE <8.0 - Info Disclosure

Title source: llm

Description

Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE.

Exploits (2)

exploitdb WORKING POC
by Ramon de C Valle · rubywebappsmultiple
https://www.exploit-db.com/exploits/38641
metasploit WORKING POC
by Ramon de C Valle · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/server/jsse_skiptls_mitm_proxy.rb

References (27)

... and 7 more

Scores

EPSS 0.6988
EPSS Percentile 98.7%

Details

Status published
Products (10)
oracle/jdk 1.5.0 update75
oracle/jdk 1.6.0 update85
oracle/jdk 1.7.0 update71 (2 CPE variants)
oracle/jdk 1.8.0 update25 (2 CPE variants)
oracle/jre 1.5.0 update75
oracle/jre 1.6.0 update85
oracle/jre 1.7.0 update71 (2 CPE variants)
oracle/jre 1.8.0 update25 (2 CPE variants)
oracle/jrockit r27.8.4
oracle/jrockit r28.3.4
Published Jan 21, 2015
Tracked Since Feb 18, 2026