CVE-2015-0478
published 2015-04-16CVE-2015-0478: Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect confidentiality via vectors…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.85%
85.3th percentile
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect confidentiality via vectors related to JCE.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | < openjdk-8 8u45-b14-1 (sid) | openjdk-8 8u45-b14-1 (sid) |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv9.3CRITICAL
vendor_ubuntu9.3CRITICAL
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2015-04-21·CVSS 9.3
CVE-2015-0460 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-0460, CVE-2015-0469)
Alexander Cherepanov discovered that OpenJDK JRE was vulnerable to
directory traversal issues with respect to handling jar files. An
attacker could use this to expose sensitive data. (CVE-2015-0480)
Florian Weimer discovered that the RSA implementation in the JCE
component in OpenJDK JRE did not follow recommended practices for
implementing RSA signatures. An attacker could use this to expose
sensitive data. (CVE-2015-0478)
A vulnerabilit
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2015-04-21·CVSS 9.3
CVE-2015-0460 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-0460, CVE-2015-0469)
Alexander Cherepanov discovered that OpenJDK JRE was vulnerable to
directory traversal issues with respect to handling jar files. An
attacker could use this to expose sensitive data. (CVE-2015-0480)
Florian Weimer discovered that the RSA implementation in the JCE
component in OpenJDK JRE did not follow recommended practices for
implementing RSA signatures. An attacker could use this to expose
sensitive data. (CVE-2015-0478)
A vulnerabilit
Red Hat
OpenJDK: insufficient hardening of RSA-CRT implementation (JCE, 8071726)
vendor_redhat·2015-04-14·CVSS 4.3
CVE-2015-0478 [MEDIUM] CWE-358 OpenJDK: insufficient hardening of RSA-CRT implementation (JCE, 8071726)
OpenJDK: insufficient hardening of RSA-CRT implementation (JCE, 8071726)
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect confidentiality via vectors related to JCE.
It was found that the RSA implementation in the JCE component in OpenJDK did not follow recommended practices for implementing RSA signatures.
Debian
CVE-2015-0478: openjdk-8 - Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JR...
vendor_debian·2015·CVSS 4.3
CVE-2015-0478 [MEDIUM] CVE-2015-0478: openjdk-8 - Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JR...
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect confidentiality via vectors related to JCE.
Scope: local
sid: resolved (fixed in 8u45-b14-1)
GHSA
GHSA-gp6q-r5x8-3f6p: Unspecified vulnerability in Oracle Java SE 5
ghsa_unreviewed·2022-05-13
CVE-2015-0478 [MEDIUM] GHSA-gp6q-r5x8-3f6p: Unspecified vulnerability in Oracle Java SE 5
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect confidentiality via vectors related to JCE.
OSV
openjdk-7 vulnerabilities
osv·2015-04-21·CVSS 9.3
CVE-2015-0460 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-0460, CVE-2015-0469)
Alexander Cherepanov discovered that OpenJDK JRE was vulnerable to
directory traversal issues with respect to handling jar files. An
attacker could use this to expose sensitive data. (CVE-2015-0480)
Florian Weimer discovered that the RSA implementation in the JCE
component in OpenJDK JRE did not follow recommended practices for
implementing RSA signatures. An attacker could use this to expose
sensitive data. (CVE-2015-0478)
A vulnerability was discovered in the OpenJDK JRE related to data
integrity. An
OSV
CVE-2015-0478: Unspecified vulnerability in Oracle Java SE 5
osv·2015-04-15·CVSS 4.3
CVE-2015-0478 [MEDIUM] CVE-2015-0478: Unspecified vulnerability in Oracle Java SE 5
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect confidentiality via vectors related to JCE.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0158.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0806.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0807.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0808.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0809.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0854.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0857.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0858.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1006.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1007.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1091.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21883640http://www-304.ibm.com/support/docview.wss?uid=swg21903565http://www-304.ibm.com/support/docview.wss?uid=swg21960194http://www.debian.org/security/2015/dsa-3234http://www.debian.org/security/2015/dsa-3235http://www.debian.org/security/2015/dsa-3316http://www.mandriva.com/security/advisories?name=MDVSA-2015:212http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.htmlhttp://www.securityfocus.com/bid/74147http://www.securitytracker.com/id/1032120http://www.securitytracker.com/id/1035517http://www.ubuntu.com/usn/USN-2573-1http://www.ubuntu.com/usn/USN-2574-1https://security.gentoo.org/glsa/201603-11http://advisories.mageia.org/MGASA-2015-0158.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0806.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0807.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0808.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0809.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0854.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0857.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0858.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1006.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1007.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1091.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21883640http://www-304.ibm.com/support/docview.wss?uid=swg21903565http://www-304.ibm.com/support/docview.wss?uid=swg21960194http://www.debian.org/security/2015/dsa-3234http://www.debian.org/security/2015/dsa-3235http://www.debian.org/security/2015/dsa-3316http://www.mandriva.com/security/advisories?name=MDVSA-2015:212http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.htmlhttp://www.securityfocus.com/bid/74147http://www.securitytracker.com/id/1032120http://www.securitytracker.com/id/1035517http://www.ubuntu.com/usn/USN-2573-1http://www.ubuntu.com/usn/USN-2574-1https://security.gentoo.org/glsa/201603-11
2015-04-16
Published