CVE-2015-0192
published 2015-07-02CVE-2015-0192: Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.54%
90.5th percentile
Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | java | >= 5.0.0.0 < 5.0.16.10 | 5.0.16.10 |
| ibm | java | 6.0.0.0 – 6.0.16.4 | — |
| ibm | java | >= 6.1.0.0 < 6.1.8.4 | 6.1.8.4 |
| ibm | java | 7.0.0.0 – 7.0.9 | — |
| ibm | java | >= 7.1.0.0 < 7.1.2.11 | 7.1.2.11 |
| ibm | java | >= 8.0 < 8.0.1.0 | 8.0.1.0 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Java 6/7/8 Virtual Machine privileges management (RHSA-2015:1006 / Nessus ID 84087)
vuldb·2026-05-28·CVSS 9.8
CVE-2015-0192 [CRITICAL] IBM Java 6/7/8 Virtual Machine privileges management (RHSA-2015:1006 / Nessus ID 84087)
A vulnerability identified as critical has been detected in IBM Java 6/7/8. Affected by this issue is some unknown functionality of the component Virtual Machine. The manipulation leads to improper privilege management.
This vulnerability is listed as CVE-2015-0192. The attack may be initiated remotely. There is no available exploit.
Applying a patch is the recommended action to fix this issue.
GHSA
GHSA-3q8x-6m7c-5p98: Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5
ghsa_unreviewed·2022-05-14
CVE-2015-0192 [HIGH] GHSA-3q8x-6m7c-5p98: Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5
Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.
Red Hat
JDK: unspecified Java sandbox restrictions bypass
vendor_redhat·2015-05-06·CVSS 7.5
CVE-2015-0192 [HIGH] JDK: unspecified Java sandbox restrictions bypass
JDK: unspecified Java sandbox restrictions bypass
Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1006.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1007.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1091.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg1IV70682http://www-01.ibm.com/support/docview.wss?uid=swg1IV70683http://www-01.ibm.com/support/docview.wss?uid=swg21883640http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1006.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1007.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1091.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg1IV70682http://www-01.ibm.com/support/docview.wss?uid=swg1IV70683http://www-01.ibm.com/support/docview.wss?uid=swg21883640
2015-07-02
Published