CVE-2015-2613Improperly Implemented Security Check for Standard in Oracle JDK

Severity
5.0MEDIUMNVD
OSV9.8
EPSS
2.7%
top 14.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 16
Latest updateMay 13

Description

Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JCE.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDoracle/jdk1.7.0, 1.8.0+1
NVDoracle/jre1.7.0, 1.8.0+1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-mg25-f862-wmh3: Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via ve2022-05-13
OSV
openjdk-7 vulnerabilities2015-07-30
OSV
CVE-2015-2613: Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via ve2015-07-16
CVEList
CVE-2015-2613: Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via ve2015-07-16

📋Vendor Advisories

5
Ubuntu
OpenJDK 6 vulnerabilities2015-08-06
Ubuntu
OpenJDK 7 vulnerabilities2015-07-30
Ubuntu
OpenJDK 7 vulnerabilities2015-07-30
Red Hat
JCE: missing EC parameter validation in ECDH_Derive() (OpenJDK JCE, 8075833)2015-07-14
Debian
CVE-2015-2613: openjdk-8 - Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, and Java SE Embedded ...2015

💬Community

1
Bugzilla
CVE-2015-2613 NSS / JCE: missing EC parameter validation in ECDH_Derive() (OpenJDK JCE, 8075833)2015-07-13
CVE-2015-2613 — Oracle JDK vulnerability | cvebase