peter bassill · operator
$ cve CVE-2015-4902 JSON

CVE-2015-4902 KEV

5.3
MEDIUM · CVSS 3.1 · EPSS 13.6% (pctl 96)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS13.6% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-284
On CISA KEVyes — remediate by 2022-03-24
Public exploitnone known
Published2015-10-22
Last modified2026-06-17

CISA KEV

NameOracle Java SE Integrity Check Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productOracle / Java SE
Ransomware usenone reported

Affected (21)

VendorProduct
opensuseleap
opensuseopensuse
oraclejdk
oraclejre
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux eus compute node
redhatenterprise linux for ibm z systems
redhatenterprise linux for ibm z systems eus
redhatenterprise linux for power big endian
redhatenterprise linux for power big endian eus
redhatenterprise linux for power little endian
redhatenterprise linux for power little endian eus
redhatenterprise linux for scientific computing
redhatenterprise linux server
redhatenterprise linux server from rhui
redhatenterprise linux workstation
redhatsatellite
suselinux enterprise module for legacy
suselinux enterprise server
suselinux enterprise software development kit

References

→ the Explorer  ·  watch your stack  ·  NVD