← Vulnerability feed

Vulnerability record · CVE-2014-3065 · published 2 December 2014

CVE-2014-3065: Ibm java code injection vulnerability

Ibm · Java

Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 before SR16 FP2 (6.0.16.2), and before SR16 FP8 (5.0.16.8) allows local users to execute arbitrary code via vectors related to the shared classes cache.

6.9 CVSS 2.0 Medium EPSS 0.56% · top 55.6% CWE-94 · Code injection
6.9CVSS 2.0 base score
0.56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 before SR16 FP2 (6.0.16.2), and before SR16 FP8 (5.0.16.8) allows local users to execute arbitrary code via vectors related to the shared classes cache.

AV:L/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00021.html
http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00027.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00033.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00036.html
http://rhn.redhat.com/errata/RHSA-2014-1876.html
http://rhn.redhat.com/errata/RHSA-2014-1877.html
http://rhn.redhat.com/errata/RHSA-2014-1880.html
http://rhn.redhat.com/errata/RHSA-2014-1881.html
http://rhn.redhat.com/errata/RHSA-2014-1882.html
http://rhn.redhat.com/errata/RHSA-2015-0264.html
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66044 Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66045 Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21688283 Vendor Advisory
http://www.securityfocus.com/bid/71147
https://bugzilla.redhat.com/show_bug.cgi?id=1162554
http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00021.html
http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00027.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00033.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00036.html
http://rhn.redhat.com/errata/RHSA-2014-1876.html
http://rhn.redhat.com/errata/RHSA-2014-1877.html
http://rhn.redhat.com/errata/RHSA-2014-1880.html
http://rhn.redhat.com/errata/RHSA-2014-1881.html
http://rhn.redhat.com/errata/RHSA-2014-1882.html
http://rhn.redhat.com/errata/RHSA-2015-0264.html
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66044 Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1IV66045 Vendor Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21688283 Vendor Advisory
http://www.securityfocus.com/bid/71147
https://bugzilla.redhat.com/show_bug.cgi?id=1162554

Track CVE-2014-3065 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-0485Ibm java vulnerabilityUnspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR13-FP16 has unknown impact and…EPSS 2.4%9.8CVE-2015-0192Ibm java improper privilege management vulnerabilityUnspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 F…EPSS 4.0%9.3CVE-2013-5456Ibm java vulnerabilityThe com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and…EPSS 6.0%9.3CVE-2013-5457Ibm java vulnerabilityUnspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to execute arbitrary code…EPSS 6.1%9.3CVE-2013-5458Ibm java vulnerabilityUnspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 5.4%9.3CVE-2013-3006Ibm java vulnerabilityUnspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availab…EPSS 4.0%9.3CVE-2013-3007Ibm java vulnerabilityUnspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 and 7 before 7 SR5 allows remote attackers to affe…EPSS 4.0%9.3CVE-2013-3008Ibm java vulnerabilityUnspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availab…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2014-3065), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.