cbcvebase.
CVE-2015-4748
published 2015-07-16

CVE-2015-4748: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to…

PriorityP262high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
44.59%
98.6th percentile
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianopenjdk-8< openjdk-8 8u66-b01-1 (sid)openjdk-8 8u66-b01-1 (sid)
dellbsafe_crypto-j< 6.2.26.2.2
oraclejdk
oraclejdk
oraclejdk
oraclejre
oraclejre
oraclejre
oraclejrockit

Detection & IOCsextracted from sources · hover to see the quote

  • Detect Java applications accepting OCSP responses that lack a nextUpdate field — these should be treated as invalid/expired rather than having unlimited validity
  • Flag Java SSL/TLS connections where a revoked X.509 certificate is accepted as valid due to a stale or missing OCSP nextUpdate — monitor for OCSP responses generated before certificate revocation being accepted
  • ·Vulnerability is in the Libraries/Security component of OpenJDK OCSP nextUpdate checking (bug 8075374); affects Java SE 6u95, 7u80, 8u45, JRockit R28.3.6, and Java SE Embedded 7u75/8u33 — fixed in Oracle Java SE 6u101, 7u85, and 8u51
  • ·Debian scope is listed as local; fixed in OpenJDK package version 8u66-b01-1 on Debian sid
  • ·OpenJDK 8 upstream patch is available at the referenced Mercurial commit; defenders should verify the patch is applied before trusting OCSP validation

CVSS provenance

nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.6HIGH
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.