5
CVE-2015-4902
- EPSS 13.35%
- Veröffentlicht 22.10.2015 00:00:03
- Zuletzt bearbeitet 22.04.2026 13:04:08
- Erkennungen
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Desktop Version 5.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Eus Version 6.7
Redhat ≫ Enterprise Linux Eus Version 7.2
Redhat ≫ Enterprise Linux Eus Version 7.3
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.5
Redhat ≫ Enterprise Linux Eus Compute Node Version 7.2
Redhat ≫ Enterprise Linux Eus Compute Node Version 7.3
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 5.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 6.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 7.0_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 6.7_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 7.2_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 7.3_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 7.4_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 7.5_s390x
Redhat ≫ Enterprise Linux For Power Big Endian Version 5.0_ppc
Redhat ≫ Enterprise Linux For Power Big Endian Version 6.0_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Version 7.0_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 6.7_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.2_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.3_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.4_ppc64
Redhat ≫ Enterprise Linux For Power Big Endian Eus Version 7.5_ppc64
Redhat ≫ Enterprise Linux For Power Little Endian Version 7.0_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 7.2_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 7.3_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 7.4_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 7.5_ppc64le
Redhat ≫ Enterprise Linux For Scientific Computing Version 6.0
Redhat ≫ Enterprise Linux For Scientific Computing Version 7.0
Redhat ≫ Enterprise Linux Server Version 5.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server From Rhui Version 5.0
Redhat ≫ Enterprise Linux Server From Rhui Version 6.0
Redhat ≫ Enterprise Linux Server From Rhui Version 7.0
Redhat ≫ Enterprise Linux Workstation Version 5.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
Suse ≫ Linux Enterprise Module For Legacy Version 12
Suse ≫ Linux Enterprise Server Version 10 Update sp4 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform -
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform vmware
Suse ≫ Linux Enterprise Server Version 11 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update -
Suse ≫ Linux Enterprise Server Version 12 Update sp1
Suse ≫ Linux Enterprise Software Development Kit Version 11 Update sp3
Suse ≫ Linux Enterprise Software Development Kit Version 11 Update sp4
Suse ≫ Linux Enterprise Software Development Kit Version 12 Update -
Suse ≫ Linux Enterprise Software Development Kit Version 12 Update sp1
03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Oracle Java SE Integrity Check Vulnerability
SchwachstelleUnspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 13.35% | 0.959 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
| CISA-ADP | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.html
https://security.gentoo.org/glsa/201603-11
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.html
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html
http://rhn.redhat.com/errata/RHSA-2015-1926.html
http://rhn.redhat.com/errata/RHSA-2015-1927.html
http://rhn.redhat.com/errata/RHSA-2015-1928.html
http://rhn.redhat.com/errata/RHSA-2015-2506.html
http://rhn.redhat.com/errata/RHSA-2015-2507.html
http://rhn.redhat.com/errata/RHSA-2015-2508.html
http://rhn.redhat.com/errata/RHSA-2015-2509.html
http://www.securitytracker.com/id/1033884
https://access.redhat.com/errata/RHSA-2016:1430
http://rhn.redhat.com/errata/RHSA-2015-2518.html
http://www.securityfocus.com/bid/77241
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-4902