peter bassill · operator
$ cve CVE-2015-2590 JSON

CVE-2015-2590 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 25.5% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS25.47% — more likely to be exploited than 98% of all CVEs
On CISA KEVyes — remediate by 2022-03-24
Public exploitnone known
Published2015-07-16
Last modified2026-06-17

CISA KEV

NameOracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productOracle / Java SE
Ransomware usenone reported

Affected (21)

VendorProduct
canonicalubuntu linux
debiandebian linux
opensuseopensuse
oraclejdk
oraclejre
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux for ibm z systems
redhatenterprise linux for ibm z systems eus
redhatenterprise linux for power big endian
redhatenterprise linux for power big endian eus
redhatenterprise linux for power little endian
redhatenterprise linux for power little endian eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatsatellite
suselinux enterprise debuginfo
suselinux enterprise desktop
suselinux enterprise server

References

→ the Explorer  ·  watch your stack  ·  NVD