5

CVE-2015-4902

Warnung
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Jdk Version 1.6.0 Update update101
Oracle ≫ Jdk Version 1.7.0 Update update85
Oracle ≫ Jdk Version 1.8.0 Update update60
Oracle ≫ Jre Version 1.6.0 Update update101
Oracle ≫ Jre Version 1.7.0 Update update85
Oracle ≫ Jre Version 1.8.0 Update update60
Redhat ≫ Satellite Version 5.6
Redhat ≫ Satellite Version 5.7
Redhat ≫ Enterprise Linux Eus Version 6.7
Redhat ≫ Enterprise Linux Eus Version 7.2
Redhat ≫ Enterprise Linux Eus Version 7.3
Redhat ≫ Enterprise Linux Eus Version 7.4
Redhat ≫ Enterprise Linux Eus Version 7.5
Opensuse ≫ Leap Version 42.1
Opensuse ≫ Opensuse Version 13.2
Suse ≫ Linux Enterprise Server Version 10 Update sp4 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform -
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwPlatform vmware
Suse ≫ Linux Enterprise Server Version 11 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update -
Suse ≫ Linux Enterprise Server Version 12 Update sp1

03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Oracle Java SE Integrity Check Vulnerability

Schwachstelle

Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.35% 0.959
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CISA-ADP 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
Patch
Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.html
Third Party Advisory
https://security.gentoo.org/glsa/201603-11
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00009.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1926.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1927.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1928.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2506.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2507.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2508.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2509.html
Third Party Advisory
http://www.securitytracker.com/id/1033884
Third Party Advisory
Broken Link
VDB Entry
https://access.redhat.com/errata/RHSA-2016:1430
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2518.html
Third Party Advisory
http://www.securityfocus.com/bid/77241
Third Party Advisory
Broken Link
VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-4902
US Government Resource