CVE-2014-8891

Unspecified vulnerability in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 5.0 before SR16-FP9, 6 before SR16-FP3, 6R1 before SR8-FP3, 7 before SR8-FP10, and 7R1 before SR2-FP10 allows remote attackers to escape the Java sandbox and execute arbitrary code via unspecified vectors related to the security manager.

Published: 2015-03-06 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2014-8891 is rated High Risk (73.4/100): CVSS Critical severity, with high exploitation likelihood (EPSS 7.30%, 94th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2014-8891

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 6.61% 7.30% +0.68%
2 2025-05-18 6.43% 6.61% +0.18%
3 2025-03-30 6.43%

Full EPSS history (14 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2014-8891

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2014-8891

OS Trackers for CVE-2014-8891

vendor priority summary link
redhat critical https://access.redhat.com/security/cve/CVE-2014-8891
suse critical CVE-2014-8891 severity critical: SUSE including 114 source package names (java-1_6_0-ibm-1.6.0_sr16.3-0.4.1, java-1_6_0-ibm-1.6.0_sr16.3-0.4.5, …), 233 product×package rows across 62 product lines (HPE Helion OpenStack 8, Image SLES12-SP5-Azure-SAP-BYOS, … (62 product lines)): Fixed 170, Known Not Affected 63. https://www.suse.com/security/cve/CVE-2014-8891/

Affected software / configurations for CVE-2014-8891

Vendor Product Version Raw CPE
ibm java_sdk >= 5.0.0.0, <= 5.0.16.8 cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*
ibm java_sdk >= 6.0.0.0, < 6.0.16.3 cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*
ibm java_sdk >= 6.1.0.0, <= 6.1.8.2 cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*
ibm java_sdk >= 7.0.0.0, < 7.0.8.10 cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*
ibm java_sdk >= 7.1.0.0, < 7.1.2.10 cpe:2.3:a:ibm:java_sdk:*:*:*:*:technology:*:*:*

References for CVE-2014-8891

URL Tags
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00021.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00022.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00025.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00027.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00033.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00036.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.html Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0136.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-0264.html Third Party Advisory
http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_February_2015 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1189142 Issue Tracking Third Party Advisory
https://www-304.ibm.com/support/docview.wss?uid=swg21695474 Vendor Advisory
cvelogic Threat Intelligence