CVE-2015-4806Improper Input Validation in Oracle JDK

Severity
6.4MEDIUMNVD
OSV5.0
EPSS
2.8%
top 13.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 21
Latest updateMay 13

Description

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages2 packages

NVDoracle/jdk1.6.0, 1.7.0, 1.8.0+2
NVDoracle/jre1.6.0, 1.7.0, 1.8.0+2

🔴Vulnerability Details

4
GHSA
GHSA-wp67-hpr4-56mq: Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality and in2022-05-13
OSV
openjdk-7 vulnerabilities2015-10-28
CVEList
CVE-2015-4806: Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality and in2015-10-21
OSV
CVE-2015-4806: Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality and in2015-10-21

📋Vendor Advisories

4
Ubuntu
OpenJDK 6 vulnerabilities2015-12-03
Ubuntu
OpenJDK 7 vulnerabilities2015-10-28
Red Hat
OpenJDK: HttpURLConnection header restriction bypass (Libraries, 8130193)2015-10-20
Debian
CVE-2015-4806: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE E...2015

💬Community

1
Bugzilla
CVE-2015-4806 OpenJDK: HttpURLConnection header restriction bypass (Libraries, 8130193)2015-06-19
CVE-2015-4806 — Improper Input Validation in Oracle JDK | cvebase