10

CVE-2015-2590

Warnung

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OracleJdk Version1.6.0 Updateupdate95
OracleJdk Version1.7.0 Updateupdate75
OracleJdk Version1.7.0 Updateupdate80
OracleJdk Version1.8.0 Updateupdate_33
OracleJdk Version1.8.0 Updateupdate45
OracleJre Version1.6.0 Updateupdate_95
OracleJre Version1.7.0 Updateupdate_75
OracleJre Version1.7.0 Updateupdate_80
OracleJre Version1.8.0 Updateupdate_33
OracleJre Version1.8.0 Updateupdate_45
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version15.04
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
SuseLinux Enterprise Debuginfo Version11 Updatesp3
SuseLinux Enterprise Debuginfo Version11 Updatesp4
OpensuseOpensuse Version13.1
OpensuseOpensuse Version13.2
SuseLinux Enterprise Desktop Version11 Updatesp3
SuseLinux Enterprise Desktop Version11 Updatesp4
SuseLinux Enterprise Desktop Version12 Update-
SuseLinux Enterprise Server Version12 Update-
RedhatSatellite Version5.6
RedhatSatellite Version5.7
RedhatEnterprise Linux Eus Version6.6
RedhatEnterprise Linux Eus Version6.7
RedhatEnterprise Linux Eus Version7.1
RedhatEnterprise Linux Eus Version7.2
RedhatEnterprise Linux Eus Version7.3
RedhatEnterprise Linux Eus Version7.4
RedhatEnterprise Linux Eus Version7.5

03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability

Schwachstelle

An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 64.62% 0.984
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
http://www.debian.org/security/2015/dsa-3316
Third Party Advisory
Mailing List
http://www.debian.org/security/2015/dsa-3339
Third Party Advisory
Mailing List
http://www.securitytracker.com/id/1032910
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/75818
Third Party Advisory
Broken Link
VDB Entry