CVE-2015-4902 KEV
5.3
MEDIUM · CVSS 3.1 · EPSS 13.6% (pctl 96)
Patch first
On CISA KEV — known exploited in the wild, due 2022-03-24.
Description
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
Scoring
| CVSS | 5.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
| EPSS | 13.6% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-284 |
| On CISA KEV | yes — remediate by 2022-03-24 |
| Public exploit | none known |
| Published | 2015-10-22 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Oracle Java SE Integrity Check Vulnerability |
|---|---|
| Added | 2022-03-03 |
| Due | 2022-03-24 |
| Vendor / product | Oracle / Java SE |
| Ransomware use | none reported |
Affected (21)
| Vendor | Product |
|---|---|
| opensuse | leap |
| opensuse | opensuse |
| oracle | jdk |
| oracle | jre |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux eus compute node |
| redhat | enterprise linux for ibm z systems |
| redhat | enterprise linux for ibm z systems eus |
| redhat | enterprise linux for power big endian |
| redhat | enterprise linux for power big endian eus |
| redhat | enterprise linux for power little endian |
| redhat | enterprise linux for power little endian eus |
| redhat | enterprise linux for scientific computing |
| redhat | enterprise linux server |
| redhat | enterprise linux server from rhui |
| redhat | enterprise linux workstation |
| redhat | satellite |
| suse | linux enterprise module for legacy |
| suse | linux enterprise server |
| suse | linux enterprise software development kit |
References
- http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html
- http://rhn.redhat.com/errata/RHSA-2015-1926.html
- http://rhn.redhat.com/errata/RHSA-2015-1927.html
- http://rhn.redhat.com/errata/RHSA-2015-1928.html
- http://rhn.redhat.com/errata/RHSA-2015-2506.html
- http://rhn.redhat.com/errata/RHSA-2015-2507.html
- http://rhn.redhat.com/errata/RHSA-2015-2508.html
- http://rhn.redhat.com/errata/RHSA-2015-2509.html
- http://rhn.redhat.com/errata/RHSA-2015-2518.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.securityfocus.com/bid/77241
- http://www.securitytracker.com/id/1033884
→ the Explorer · watch your stack · NVD