CVE-2015-4748
published 2015-07-16CVE-2015-4748: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to…
PriorityP262high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
44.59%
98.6th percentile
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | < openjdk-8 8u66-b01-1 (sid) | openjdk-8 8u66-b01-1 (sid) |
| dell | bsafe_crypto-j | < 6.2.2 | 6.2.2 |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect Java applications accepting OCSP responses that lack a nextUpdate field — these should be treated as invalid/expired rather than having unlimited validity ↗
- →Flag Java SSL/TLS connections where a revoked X.509 certificate is accepted as valid due to a stale or missing OCSP nextUpdate — monitor for OCSP responses generated before certificate revocation being accepted ↗
- ·Vulnerability is in the Libraries/Security component of OpenJDK OCSP nextUpdate checking (bug 8075374); affects Java SE 6u95, 7u80, 8u45, JRockit R28.3.6, and Java SE Embedded 7u75/8u33 — fixed in Oracle Java SE 6u101, 7u85, and 8u51 ↗
- ·Debian scope is listed as local; fixed in OpenJDK package version 8u66-b01-1 on Debian sid ↗
- ·OpenJDK 8 upstream patch is available at the referenced Mercurial commit; defenders should verify the patch is applied before trusting OCSP validation ↗
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.6HIGH
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fvmj-2grm-x9mr: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28
ghsa_unreviewed·2022-05-13
CVE-2015-4748 [HIGH] GHSA-fvmj-2grm-x9mr: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.
GHSA
GHSA-xm3c-w6gm-7q8v: An issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6
ghsa_unreviewed·2022-05-13·CVSS 7.6
CVE-2016-8212 [HIGH] CWE-404 GHSA-xm3c-w6gm-7q8v: An issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6
An issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6.2.2. There is an Improper OCSP Validation Vulnerability. OCSP responses have two time values: thisUpdate and nextUpdate. These specify a validity period; however, both values are optional. Crypto-J treats the lack of a nextUpdate as indicating that the OCSP response is valid indefinitely instead of restricting its validity for a brief period surrounding the thisUpdate time. This vulnerability is similar to the issue described in CVE-2015-4748.
OSV
openjdk-7 vulnerabilities
osv·2015-07-30·CVSS 9.8
CVE-2015-2590 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a security improvement, this update modifies OpenJDK behavior to
reject
OSV
CVE-2015-4748: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28
osv·2015-07-16·CVSS 7.6
CVE-2015-4748 [HIGH] CVE-2015-4748: Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2015-08-06·CVSS 9.8
CVE-2015-2590 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a secu
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2015-07-30·CVSS 9.8
CVE-2015-2808 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a secu
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2015-07-30·CVSS 9.8
CVE-2015-2613 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731,
CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748)
Several vulnerabilities were discovered in the cryptographic components
of the OpenJDK JRE. An attacker could exploit these to expose sensitive
data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000,
CVE-2015-2625, CVE-2015-2613)
As a security improvement, this update modifies OpenJDK behavior to
disable RC4 TLS/SSL cipher suites by default.
As a security improvement, this
Red Hat
OpenJDK: incorrect OCSP nextUpdate checking (Libraries, 8075374)
vendor_redhat·2015-07-14·CVSS 7.6
CVE-2015-4748 [HIGH] CWE-299 OpenJDK: incorrect OCSP nextUpdate checking (Libraries, 8075374)
OpenJDK: incorrect OCSP nextUpdate checking (Libraries, 8075374)
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.
A flaw was found in the way the Libraries component of OpenJDK verified Online Certificate Status Protocol (OCSP) responses. An OCSP response with no nextUpdate date specified was incorrectly handled as having unlimited validity, possibly causing a revoked X.509 certificate to be interpreted as valid.
Debian
CVE-2015-4748: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3....
vendor_debian·2015·CVSS 7.6
CVE-2015-4748 [HIGH] CVE-2015-4748: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3....
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.
Scope: local
sid: resolved (fixed in 8u66-b01-1)
No detection rules found.
No public exploits indexed.
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1228.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1229.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1230.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1241.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1242.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1243.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1485.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1486.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1488.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1526.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1544.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1604.htmlhttp://www.debian.org/security/2015/dsa-3316http://www.debian.org/security/2015/dsa-3339http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/75854http://www.securitytracker.com/id/1032910http://www.securitytracker.com/id/1037732http://www.ubuntu.com/usn/USN-2696-1http://www.ubuntu.com/usn/USN-2706-1https://kc.mcafee.com/corporate/index?page=content&id=SB10139https://security.gentoo.org/glsa/201603-11https://security.gentoo.org/glsa/201603-14http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1228.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1229.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1230.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1241.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1242.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1243.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1485.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1486.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1488.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1526.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1544.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1604.htmlhttp://www.debian.org/security/2015/dsa-3316http://www.debian.org/security/2015/dsa-3339http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/75854http://www.securitytracker.com/id/1032910http://www.securitytracker.com/id/1037732http://www.ubuntu.com/usn/USN-2696-1http://www.ubuntu.com/usn/USN-2706-1https://kc.mcafee.com/corporate/index?page=content&id=SB10139https://security.gentoo.org/glsa/201603-11https://security.gentoo.org/glsa/201603-14
2015-07-16
Published