CVE-2015-0488
published 2015-04-16CVE-2015-0488: Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect availability via vectors…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.20%
89.8th percentile
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect availability via vectors related to JSSE.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | < openjdk-8 8u45-b14-1 (sid) | openjdk-8 8u45-b14-1 (sid) |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv9.3CRITICAL
vendor_ubuntu9.3CRITICAL
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2015-04-21·CVSS 9.3
CVE-2015-0460 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-0460, CVE-2015-0469)
Alexander Cherepanov discovered that OpenJDK JRE was vulnerable to
directory traversal issues with respect to handling jar files. An
attacker could use this to expose sensitive data. (CVE-2015-0480)
Florian Weimer discovered that the RSA implementation in the JCE
component in OpenJDK JRE did not follow recommended practices for
implementing RSA signatures. An attacker could use this to expose
sensitive data. (CVE-2015-0478)
A vulnerabilit
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2015-04-21·CVSS 9.3
CVE-2015-0460 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-0460, CVE-2015-0469)
Alexander Cherepanov discovered that OpenJDK JRE was vulnerable to
directory traversal issues with respect to handling jar files. An
attacker could use this to expose sensitive data. (CVE-2015-0480)
Florian Weimer discovered that the RSA implementation in the JCE
component in OpenJDK JRE did not follow recommended practices for
implementing RSA signatures. An attacker could use this to expose
sensitive data. (CVE-2015-0478)
A vulnerabilit
Red Hat
OpenJDK: certificate options parsing uncaught exception (JSSE, 8068720)
vendor_redhat·2015-04-14·CVSS 5.0
CVE-2015-0488 [MEDIUM] CWE-248 OpenJDK: certificate options parsing uncaught exception (JSSE, 8068720)
OpenJDK: certificate options parsing uncaught exception (JSSE, 8068720)
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect availability via vectors related to JSSE.
A flaw was found in the way the JSSE component in OpenJDK parsed X.509 certificate options. A specially crafted certificate could cause JSSE to raise an exception, possibly causing an application using JSSE to exit unexpectedly.
Debian
CVE-2015-0488: openjdk-8 - Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JR...
vendor_debian·2015·CVSS 5.0
CVE-2015-0488 [MEDIUM] CVE-2015-0488: openjdk-8 - Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JR...
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect availability via vectors related to JSSE.
Scope: local
sid: resolved (fixed in 8u45-b14-1)
GHSA
GHSA-942j-rfmc-q4mq: Unspecified vulnerability in Oracle Java SE 5
ghsa_unreviewed·2022-05-13
CVE-2015-0488 [MEDIUM] GHSA-942j-rfmc-q4mq: Unspecified vulnerability in Oracle Java SE 5
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect availability via vectors related to JSSE.
OSV
openjdk-7 vulnerabilities
osv·2015-04-21·CVSS 9.3
CVE-2015-0460 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-0460, CVE-2015-0469)
Alexander Cherepanov discovered that OpenJDK JRE was vulnerable to
directory traversal issues with respect to handling jar files. An
attacker could use this to expose sensitive data. (CVE-2015-0480)
Florian Weimer discovered that the RSA implementation in the JCE
component in OpenJDK JRE did not follow recommended practices for
implementing RSA signatures. An attacker could use this to expose
sensitive data. (CVE-2015-0478)
A vulnerability was discovered in the OpenJDK JRE related to data
integrity. An
OSV
CVE-2015-0488: Unspecified vulnerability in Oracle Java SE 5
osv·2015-04-15·CVSS 5.0
CVE-2015-0488 [MEDIUM] CVE-2015-0488: Unspecified vulnerability in Oracle Java SE 5
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect availability via vectors related to JSSE.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0158.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0806.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0807.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0808.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0809.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0854.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0857.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0858.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1006.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1007.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1091.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21883640http://www-304.ibm.com/support/docview.wss?uid=swg21903565http://www-304.ibm.com/support/docview.wss?uid=swg21960194http://www-304.ibm.com/support/docview.wss?uid=swg21960769http://www.debian.org/security/2015/dsa-3234http://www.debian.org/security/2015/dsa-3235http://www.debian.org/security/2015/dsa-3316http://www.mandriva.com/security/advisories?name=MDVSA-2015:212http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.htmlhttp://www.securityfocus.com/bid/74111http://www.securitytracker.com/id/1032120http://www.ubuntu.com/usn/USN-2573-1http://www.ubuntu.com/usn/USN-2574-1https://security.gentoo.org/glsa/201603-11http://advisories.mageia.org/MGASA-2015-0158.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-05/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0806.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0807.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0808.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0809.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0854.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0857.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0858.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1006.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1007.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1091.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21883640http://www-304.ibm.com/support/docview.wss?uid=swg21903565http://www-304.ibm.com/support/docview.wss?uid=swg21960194http://www-304.ibm.com/support/docview.wss?uid=swg21960769http://www.debian.org/security/2015/dsa-3234http://www.debian.org/security/2015/dsa-3235http://www.debian.org/security/2015/dsa-3316http://www.mandriva.com/security/advisories?name=MDVSA-2015:212http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.htmlhttp://www.securityfocus.com/bid/74111http://www.securitytracker.com/id/1032120http://www.ubuntu.com/usn/USN-2573-1http://www.ubuntu.com/usn/USN-2574-1https://security.gentoo.org/glsa/201603-11
2015-04-16
Published