CVE-2014-6517: Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and Jrockit R27.8.3 and R28.3.3
infovulnerability
security
Summary
CVE-2014-6517 is an unspecified security vulnerability in multiple versions of Oracle Java SE (a widely-used programming language and runtime environment) and related products that allows remote attackers to compromise confidentiality through JAXP (Java API for XML Processing, a tool for handling XML data). The vulnerability affects Java SE versions 6u81, 7u67, and 8u20, among others, but the specific technical details of how it works were not disclosed.
Vulnerability Details
CVSS Score
5
EPSS (30-day exploit probability)
EPSS: 2.8%
Classification
Attack SophisticationModerate
Original source: https://nvd.nist.gov/vuln/detail/CVE-2014-6517
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%