CVE-2015-4902
medium · 5.3Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-03-03Remediation due 2022-03-24
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
5.3
CVSS
13.6%
EPSS (exploit prob.)
96th
EPSS percentile
2015-10-22
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weaknesses
CWE-284
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| oracle | jdk | 1.6.0 |
| oracle | jdk | 1.7.0 |
| oracle | jdk | 1.8.0 |
| oracle | jre | 1.6.0 |
| oracle | jre | 1.7.0 |
| oracle | jre | 1.8.0 |
| redhat | satellite | 5.6 |
| redhat | satellite | 5.7 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_eus | 6.7 |
| redhat | enterprise_linux_eus | 7.2 |
| redhat | enterprise_linux_eus | 7.3 |
| redhat | enterprise_linux_eus | 7.4 |
| redhat | enterprise_linux_eus | 7.5 |
| redhat | enterprise_linux_eus_compute_node | 7.2 |
| redhat | enterprise_linux_eus_compute_node | 7.3 |
| redhat | enterprise_linux_for_ibm_z_systems | 5.0_s390x |
| redhat | enterprise_linux_for_ibm_z_systems | 6.0_s390x |
| redhat | enterprise_linux_for_ibm_z_systems | 7.0_s390x |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 6.7_s390x |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 7.2_s390x |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 7.3_s390x |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 7.4_s390x |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 7.5_s390x |
| redhat | enterprise_linux_for_power_big_endian | 5.0_ppc |
| redhat | enterprise_linux_for_power_big_endian | 6.0_ppc64 |
| redhat | enterprise_linux_for_power_big_endian | 7.0_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 6.7_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.2_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.3_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.4_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 7.5_ppc64 |
| redhat | enterprise_linux_for_power_little_endian | 7.0_ppc64le |
| redhat | enterprise_linux_for_power_little_endian_eus | 7.2_ppc64le |
| redhat | enterprise_linux_for_power_little_endian_eus | 7.3_ppc64le |
| redhat | enterprise_linux_for_power_little_endian_eus | 7.4_ppc64le |
| redhat | enterprise_linux_for_power_little_endian_eus | 7.5_ppc64le |
| redhat | enterprise_linux_for_scientific_computing | 6.0 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html
- http://rhn.redhat.com/errata/RHSA-2015-1926.html
- http://rhn.redhat.com/errata/RHSA-2015-1927.html
- http://rhn.redhat.com/errata/RHSA-2015-1928.html
- http://rhn.redhat.com/errata/RHSA-2015-2506.html
- http://rhn.redhat.com/errata/RHSA-2015-2507.html
- http://rhn.redhat.com/errata/RHSA-2015-2508.html
- http://rhn.redhat.com/errata/RHSA-2015-2509.html
- http://rhn.redhat.com/errata/RHSA-2015-2518.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.securityfocus.com/bid/77241
- http://www.securitytracker.com/id/1033884
- https://access.redhat.com/errata/RHSA-2016:1430
- https://security.gentoo.org/glsa/201603-11
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-4902