10

CVE-2015-2590

Warnung
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Jdk Version 1.6.0 Update update95
Oracle ≫ Jdk Version 1.7.0 Update update75
Oracle ≫ Jdk Version 1.7.0 Update update80
Oracle ≫ Jdk Version 1.8.0 Update update33
Oracle ≫ Jdk Version 1.8.0 Update update45
Oracle ≫ Jre Version 1.6.0 Update update95
Oracle ≫ Jre Version 1.7.0 Update update75
Oracle ≫ Jre Version 1.7.0 Update update80
Oracle ≫ Jre Version 1.8.0 Update update33
Oracle ≫ Jre Version 1.8.0 Update update45
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 15.04
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp3
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp4
Opensuse ≫ Opensuse Version 13.1
Opensuse ≫ Opensuse Version 13.2
Suse ≫ Linux Enterprise Desktop Version 11 Update sp3
Suse ≫ Linux Enterprise Desktop Version 11 Update sp4
Suse ≫ Linux Enterprise Desktop Version 12 Update -
Suse ≫ Linux Enterprise Server Version 12 Update -
Redhat ≫ Satellite Version 5.6
Redhat ≫ Satellite Version 5.7
Redhat ≫ Enterprise Linux Eus Version 6.6
Redhat ≫ Enterprise Linux Eus Version 6.7
Redhat ≫ Enterprise Linux Eus Version 7.1
Redhat ≫ Enterprise Linux Eus Version 7.2
Redhat ≫ Enterprise Linux Eus Version 7.3
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.5

03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability

Schwachstelle

An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 25.47% 0.977
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
Patch
Vendor Advisory
https://security.gentoo.org/glsa/201603-14
Third Party Advisory
https://security.gentoo.org/glsa/201603-11
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.html
Third Party Advisory
Mailing List
http://rhn.redhat.com/errata/RHSA-2015-1228.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1229.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1230.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1241.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1242.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1243.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1526.html
Third Party Advisory
http://www.debian.org/security/2015/dsa-3316
Third Party Advisory
Mailing List
http://www.debian.org/security/2015/dsa-3339
Third Party Advisory
Mailing List
http://www.securitytracker.com/id/1032910
Third Party Advisory
Broken Link
VDB Entry
http://www.ubuntu.com/usn/USN-2696-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2706-1
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1485.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1486.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1488.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1544.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1604.html
Third Party Advisory
http://www.securityfocus.com/bid/75818
Third Party Advisory
Broken Link
VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2590
US Government Resource