10

CVE-2015-2590

Warning

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.

Data is provided by the National Vulnerability Database (NVD)
OracleJdk Version1.6.0 Updateupdate95
OracleJdk Version1.7.0 Updateupdate75
OracleJdk Version1.7.0 Updateupdate80
OracleJdk Version1.8.0 Updateupdate_33
OracleJdk Version1.8.0 Updateupdate45
OracleJre Version1.6.0 Updateupdate_95
OracleJre Version1.7.0 Updateupdate_75
OracleJre Version1.7.0 Updateupdate_80
OracleJre Version1.8.0 Updateupdate_33
OracleJre Version1.8.0 Updateupdate_45
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version15.04
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
SuseLinux Enterprise Debuginfo Version11 Updatesp3
SuseLinux Enterprise Debuginfo Version11 Updatesp4
OpensuseOpensuse Version13.1
OpensuseOpensuse Version13.2
SuseLinux Enterprise Desktop Version11 Updatesp3
SuseLinux Enterprise Desktop Version11 Updatesp4
SuseLinux Enterprise Desktop Version12 Update-
SuseLinux Enterprise Server Version12 Update-
RedhatSatellite Version5.6
RedhatSatellite Version5.7
RedhatEnterprise Linux Eus Version6.6
RedhatEnterprise Linux Eus Version6.7
RedhatEnterprise Linux Eus Version7.1
RedhatEnterprise Linux Eus Version7.2
RedhatEnterprise Linux Eus Version7.3
RedhatEnterprise Linux Eus Version7.4
RedhatEnterprise Linux Eus Version7.5

03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability

Vulnerability

An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 64.62% 0.984
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
http://www.debian.org/security/2015/dsa-3316
Third Party Advisory
Mailing List
http://www.debian.org/security/2015/dsa-3339
Third Party Advisory
Mailing List
http://www.securitytracker.com/id/1032910
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/75818
Third Party Advisory
Broken Link
VDB Entry