Description:
eHealth Fails Security scan:
Title: Multiple Vulnerabilities in Oracle Java SE
IAVM Notice Number: 2014-A-0010 Revision Number: 0.0
References: Critical Patch Update Jan 2014 Patch Availability Document for
Oracle Java SE (Doc ID 1607034.1)
https://support.oracle.com/epmos/faces/DocumentDisplay?_afrLoop=168026268171
14&id=1607034.1&_afrWindowMode=0&_adf.ctrl-state=1b100ura6y_216
Oracle Critical Patch Update Advisory - January 2014
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
Symantec Deepsight BID 64863, 64875, 64882, 64890, 64894, 64899, 64903,
64906, 64907, 64910, 64912, 64914, 64915, 64916, 64917, 64918, 64919, 64920,
64921, 64922, 64923, 64924, 64925, 64926, 64927, 64928, 64929, 64930, 64931,
64932, 64933, 64934, 64935, 64936, 64937 (requires account)
https://tms.symantec.com/
STIG Finding Severity: Category I
CVEs:
CVE-2013-5870
CVE-2013-5878
CVE-2013-5884
CVE-2013-5887
CVE-2013-5888
CVE-2013-5889
CVE-2013-5893
CVE-2013-5895
CVE-2013-5896
CVE-2013-5898
CVE-2013-5899
CVE-2013-5902
CVE-2013-5904
CVE-2013-5905
CVE-2013-5906
CVE-2013-5907
CVE-2013-5910
CVE-2014-0368
CVE-2014-0373
CVE-2014-0375
CVE-2014-0376
CVE-2014-0382
CVE-2014-0387
CVE-2014-0403
CVE-2014-0408
CVE-2014-0410
CVE-2014-0411
CVE-2014-0415
CVE-2014-0416
CVE-2014-0417
CVE-2014-0418
CVE-2014-0422
CVE-2014-0423
CVE-2014-0424
CVE-2014-0428
Solution:
The latest version of java will be updated in 6.3.2.05 currently scheduled for June 2014.