{"id":21880,"date":"2014-01-15T12:59:32","date_gmt":"2014-01-15T20:59:32","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=21880"},"modified":"2016-10-06T12:39:00","modified_gmt":"2016-10-06T19:39:00","slug":"oracle-patches-java-security-vulnerabilities","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/","title":{"rendered":"Oracle Patches Java Security Vulnerabilities"},"content":{"rendered":"<p><a href=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/01\/java-security-header.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9725\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/01\/java-security-header.jpg\" alt=\"java-security-header\" width=\"660\" height=\"370\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/01\/java-security-header.jpg 660w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/01\/java-security-header-150x84.jpg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/01\/java-security-header-300x168.jpg 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/01\/java-security-header-657x368.jpg 657w\" sizes=\"auto, (max-width: 660px) 100vw, 660px\" \/><\/a><\/p>\n<p>Yesterday, Oracle issued a <a href=\"http:\/\/www.oracle.com\/technetwork\/topics\/security\/cpujan2014-1972949.html\" target=\"_blank\">critical patch update<\/a> for multiple security vulnerabilities in Java with the release of Java SE 7u51. Oracle&#8217;s Java update fixes 36 vulnerabilities, 34 of which are remotely exploitable without authentication.<\/p>\n<p>Oracle notes:<\/p>\n<blockquote><p>These vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password.<\/p><\/blockquote>\n<p>Supported versions that are affected: Java SE 5.0u55, Java SE 6u65, Java SE 7u45, Java SE 7u45 on OS X, Java SE 7u45 on Firefox, JRockit R27.7.7, JRockit R28.2.9, Java SE Embedded 7u45, and JavaFX 2.2.45.<\/p>\n<p>As typical of Oracle&#8217;s Java updates, which occur quarterly instead of monthly, a colossal 36 bugs were fixed in this update. So it&#8217;s important that you update to Java SE 7u51\u00a0immediately to mitigate potential threats.<\/p>\n<p>Following is a complete list of all 36 vulnerabilities resolved in the Oracle Java SE update:<\/p>\n<ul>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5870\" target=\"_blank\">CVE-2013-5870<\/a> : Vulnerability in the Java SE, JavaFX component of Oracle Java SE (subcomponent: JavaFX). Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE, JavaFX accessible data as well as read access to a subset of Java SE, JavaFX accessible data and ability to cause a partial denial of service (partial DOS) of Java SE, JavaFX.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5878\" target=\"_blank\">CVE-2013-5878<\/a> : Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE, Java SE Embedded accessible data as well as read access to a subset of Java SE, Java SE Embedded accessible data and ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5884\" target=\"_blank\">CVE-2013-5884<\/a> : Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: CORBA). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5887\" target=\"_blank\">CVE-2013-5887<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5888\" target=\"_blank\">CVE-2013-5888<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Easily exploitable vulnerability requiring logon to Operating System. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE accessible data as well as read access to a subset of Java SE accessible data and ability to cause a partial denial of service (partial DOS) of Java SE.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5889\" target=\"_blank\">CVE-2013-5889<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5893\" target=\"_blank\">CVE-2013-5893<\/a> : Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5895\" target=\"_blank\">CVE-2013-5895<\/a> : Vulnerability in the Java SE, JavaFX component of Oracle Java SE (subcomponent: JavaFX). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized read access to a subset of Java SE, JavaFX accessible data.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5896\" target=\"_blank\">CVE-2013-5896<\/a> : Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: CORBA). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5898\" target=\"_blank\">CVE-2013-5898<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Very difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE accessible data as well as read access to a subset of Java SE accessible data.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5899\" target=\"_blank\">CVE-2013-5899<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5902\" target=\"_blank\">CVE-2013-5902<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE accessible data as well as read access to a subset of Java SE accessible data and ability to cause a partial denial of service (partial DOS) of Java SE.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5904\" target=\"_blank\">CVE-2013-5904<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE accessible data as well as read access to a subset of Java SE accessible data and ability to cause a partial denial of service (partial DOS) of Java SE.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5905\" target=\"_blank\">CVE-2013-5905<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install). Very difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE accessible data as well as read access to a subset of Java SE accessible data and ability to cause a partial denial of service (partial DOS) of Java SE.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5906\" target=\"_blank\">CVE-2013-5906<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install). Very difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE accessible data as well as read access to a subset of Java SE accessible data and ability to cause a partial denial of service (partial DOS) of Java SE.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5907\" target=\"_blank\">CVE-2013-5907<\/a> : Vulnerability in the Java SE, JRockit, Java SE Embedded component of Oracle Java SE (subcomponent: 2D). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2013-5910\" target=\"_blank\">CVE-2013-5910<\/a> : Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE, Java SE Embedded accessible data.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0368\" target=\"_blank\">CVE-2014-0368<\/a> : Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0373\" target=\"_blank\">CVE-2014-0373<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Serviceability). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE accessible data as well as read access to a subset of Java SE accessible data and ability to cause a partial denial of service (partial DOS) of Java SE.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0375\" target=\"_blank\">CVE-2014-0375<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE accessible data as well as read access to a subset of Java SE accessible data.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0376\" target=\"_blank\">CVE-2014-0376<\/a> : Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE, Java SE Embedded accessible data.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0382\" target=\"_blank\">CVE-2014-0382<\/a> : Vulnerability in the Java SE, JavaFX component of Oracle Java SE (subcomponent: JavaFX). Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JavaFX.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0385\" target=\"_blank\">CVE-2014-0385<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install). Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0387\" target=\"_blank\">CVE-2014-0387<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0403\" target=\"_blank\">CVE-2014-0403<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE accessible data as well as read access to a subset of Java SE accessible data.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0408\" target=\"_blank\">CVE-2014-0408<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Hotspot). Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0410\" target=\"_blank\">CVE-2014-0410<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0411\" target=\"_blank\">CVE-2014-0411<\/a> : Vulnerability in the Java SE, JRockit, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Very difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL\/TLS. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE, JRockit, Java SE Embedded accessible data as well as read access to a subset of Java SE, JRockit, Java SE Embedded accessible data.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0415\" target=\"_blank\">CVE-2014-0415<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0416\" target=\"_blank\">CVE-2014-0416<\/a> : Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAAS). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE, Java SE Embedded accessible data.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0417\" target=\"_blank\">CVE-2014-0417<\/a> : Vulnerability in the Java SE, JavaFX, Java SE Embedded component of Oracle Java SE (subcomponent: 2D). Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0418\" target=\"_blank\">CVE-2014-0418<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE accessible data as well as read access to a subset of Java SE accessible data and ability to cause a partial denial of service (partial DOS) of Java SE.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0422\" target=\"_blank\">CVE-2014-0422<\/a> : Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JNDI). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0423\" target=\"_blank\">CVE-2014-0423<\/a> : Vulnerability in the Java SE, JRockit, Java SE Embedded component of Oracle Java SE (subcomponent: Beans). Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized read access to a subset of Java SE, JRockit, Java SE Embedded accessible data and ability to cause a partial denial of service (partial DOS) of Java SE, JRockit, Java SE Embedded.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0424\" target=\"_blank\">CVE-2014-0424<\/a> : Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java SE accessible data as well as read access to a subset of Java SE accessible data and ability to cause a partial denial of service (partial DOS) of Java SE.<\/li>\n<li><a href=\"http:\/\/www.cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-0428\" target=\"_blank\">CVE-2014-0428<\/a> : Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: CORBA). Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.<\/li>\n<\/ul>\n<p>Users can go to Oracle\u2019s website to <a title=\"Java SE - Downloads\" href=\"http:\/\/www.oracle.com\/technetwork\/java\/javase\/downloads\/index.html\" target=\"_blank\">download Java SE 7u51<\/a> as advised. Windows and Mac OS X users can also use automatic updates to get the latest release.\u00a0Users running Java SE with a browser can download the latest release from <a href=\"http:\/\/java.com\/\" target=\"_blank\">Java.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Yesterday, Oracle issued a critical patch update for multiple security vulnerabilities in Java with the release of Java SE 7u51. Oracle&#8217;s Java update fixes 36 vulnerabilities, 34 of which are remotely exploitable without authentication. Oracle notes: These vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":9921,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[261,75,459,861,183,143],"class_list":["post-21880","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security-news","tag-bug-fixes","tag-java","tag-java-se","tag-java-se-7u51","tag-oracle","tag-vulnerabilities"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Yesterday, Oracle issued a critical patch update for multiple security vulnerabilities in Java with the release of Java SE 7u51. Oracle&#039;s Java update fixes 36 vulnerabilities, 34 of which are remotely exploitable without authentication. Oracle notes: These vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Derek Erwin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"The Mac Security Blog - Keep Macs safe from the dangers of the Internet\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Oracle Patches Java Security Vulnerabilities\" \/>\n\t\t<meta property=\"og:description\" content=\"Yesterday, Oracle issued a critical patch update for multiple security vulnerabilities in Java with the release of Java SE 7u51. Oracle&#039;s Java update fixes 36 vulnerabilities, 34 of which are remotely exploitable without authentication. Oracle notes: These vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2014-01-15T20:59:32+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2016-10-06T19:39:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/integogroup\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@IntegoSecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Oracle Patches Java Security Vulnerabilities\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Yesterday, Oracle issued a critical patch update for multiple security vulnerabilities in Java with the release of Java SE 7u51. Oracle&#039;s Java update fixes 36 vulnerabilities, 34 of which are remotely exploitable without authentication. Oracle notes: These vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@IntegoSecurity\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/#blogposting\",\"name\":\"Oracle Patches Java Security Vulnerabilities\",\"headline\":\"Oracle Patches Java Security Vulnerabilities\",\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/derek-erwin\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2013\\\/01\\\/Java-Security-Update-Tile.png\",\"width\":400,\"height\":260,\"caption\":\"Java security updates\"},\"datePublished\":\"2014-01-15T12:59:32-08:00\",\"dateModified\":\"2016-10-06T12:39:00-07:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/#webpage\"},\"articleSection\":\"Security News, Bug Fixes, Java, Java SE, Java SE 7u51, Oracle, Vulnerabilities\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"position\":2,\"name\":\"Security News\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/#listItem\",\"name\":\"Oracle Patches Java Security Vulnerabilities\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/#listItem\",\"position\":3,\"name\":\"Oracle Patches Java Security Vulnerabilities\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/logo2.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/#organizationLogo\",\"width\":122,\"height\":46},\"image\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/integogroup\\\/\",\"https:\\\/\\\/x.com\\\/IntegoSecurity\",\"https:\\\/\\\/www.instagram.com\\\/intego_security\\\/\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/IntegoVideo\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/intego\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/derek-erwin\\\/#author\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/derek-erwin\\\/\",\"name\":\"Derek Erwin\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/badd54c0d1d2f3c4c8497e8a892a5b6cdb00b21e0df10fbea205ab1453e29428?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Derek Erwin\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/#webpage\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/\",\"name\":\"Oracle Patches Java Security Vulnerabilities\",\"description\":\"Yesterday, Oracle issued a critical patch update for multiple security vulnerabilities in Java with the release of Java SE 7u51. Oracle's Java update fixes 36 vulnerabilities, 34 of which are remotely exploitable without authentication. Oracle notes: These vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/derek-erwin\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/derek-erwin\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2013\\\/01\\\/Java-Security-Update-Tile.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/#mainImage\",\"width\":400,\"height\":260,\"caption\":\"Java security updates\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oracle-patches-java-security-vulnerabilities\\\/#mainImage\"},\"datePublished\":\"2014-01-15T12:59:32-08:00\",\"dateModified\":\"2016-10-06T12:39:00-07:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Oracle Patches Java Security Vulnerabilities<\/title>\n\n","aioseo_head_json":{"title":"Oracle Patches Java Security Vulnerabilities","description":"Yesterday, Oracle issued a critical patch update for multiple security vulnerabilities in Java with the release of Java SE 7u51. Oracle's Java update fixes 36 vulnerabilities, 34 of which are remotely exploitable without authentication. Oracle notes: These vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for","canonical_url":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/#blogposting","name":"Oracle Patches Java Security Vulnerabilities","headline":"Oracle Patches Java Security Vulnerabilities","author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/derek-erwin\/#author"},"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/01\/Java-Security-Update-Tile.png","width":400,"height":260,"caption":"Java security updates"},"datePublished":"2014-01-15T12:59:32-08:00","dateModified":"2016-10-06T12:39:00-07:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/#webpage"},"isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/#webpage"},"articleSection":"Security News, Bug Fixes, Java, Java SE, Java SE 7u51, Oracle, Vulnerabilities"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","position":2,"name":"Security News","item":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/#listItem","name":"Oracle Patches Java Security Vulnerabilities"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/#listItem","position":3,"name":"Oracle Patches Java Security Vulnerabilities","previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}}]},{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","url":"https:\/\/www.intego.com\/mac-security-blog\/","logo":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2026\/08\/logo2.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/#organizationLogo","width":122,"height":46},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/integogroup\/","https:\/\/x.com\/IntegoSecurity","https:\/\/www.instagram.com\/intego_security\/","https:\/\/www.youtube.com\/user\/IntegoVideo","https:\/\/www.linkedin.com\/company\/intego"]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/derek-erwin\/#author","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/derek-erwin\/","name":"Derek Erwin","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/badd54c0d1d2f3c4c8497e8a892a5b6cdb00b21e0df10fbea205ab1453e29428?s=96&d=mm&r=g","width":96,"height":96,"caption":"Derek Erwin"}},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/","name":"Oracle Patches Java Security Vulnerabilities","description":"Yesterday, Oracle issued a critical patch update for multiple security vulnerabilities in Java with the release of Java SE 7u51. Oracle's Java update fixes 36 vulnerabilities, 34 of which are remotely exploitable without authentication. Oracle notes: These vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/#breadcrumblist"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/derek-erwin\/#author"},"creator":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/derek-erwin\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/01\/Java-Security-Update-Tile.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/#mainImage","width":400,"height":260,"caption":"Java security updates"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/#mainImage"},"datePublished":"2014-01-15T12:59:32-08:00","dateModified":"2016-10-06T12:39:00-07:00"},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"The Mac Security Blog - Keep Macs safe from the dangers of the Internet","og:type":"article","og:title":"Oracle Patches Java Security Vulnerabilities","og:description":"Yesterday, Oracle issued a critical patch update for multiple security vulnerabilities in Java with the release of Java SE 7u51. Oracle's Java update fixes 36 vulnerabilities, 34 of which are remotely exploitable without authentication. Oracle notes: These vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for","og:url":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/","article:published_time":"2014-01-15T20:59:32+00:00","article:modified_time":"2016-10-06T19:39:00+00:00","article:publisher":"https:\/\/www.facebook.com\/integogroup\/","twitter:card":"summary_large_image","twitter:site":"@IntegoSecurity","twitter:title":"Oracle Patches Java Security Vulnerabilities","twitter:description":"Yesterday, Oracle issued a critical patch update for multiple security vulnerabilities in Java with the release of Java SE 7u51. Oracle's Java update fixes 36 vulnerabilities, 34 of which are remotely exploitable without authentication. Oracle notes: These vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for","twitter:creator":"@IntegoSecurity"},"aioseo_meta_data":{"post_id":"21880","title":null,"description":null,"keywords":null,"keyphrases":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":null,"twitter_description":null,"schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-09-03 17:08:32","created":"2026-09-03 17:08:32","updated":"2026-09-04 13:27:01","reviewed_by":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/\" title=\"Security News\">Security News<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tOracle Patches Java Security Vulnerabilities\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.intego.com\/mac-security-blog"},{"label":"Security News","link":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/"},{"label":"Oracle Patches Java Security Vulnerabilities","link":"https:\/\/www.intego.com\/mac-security-blog\/oracle-patches-java-security-vulnerabilities\/"}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/21880","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=21880"}],"version-history":[{"count":19,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/21880\/revisions"}],"predecessor-version":[{"id":58120,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/21880\/revisions\/58120"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/9921"}],"wp:attachment":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=21880"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=21880"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=21880"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}