CVE-2015-4871
published 2015-10-21CVE-2015-4871: Unspecified vulnerability in Oracle Java SE 7u85 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.
PriorityP434medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
3.04%
86.1th percentile
Unspecified vulnerability in Oracle Java SE 7u85 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gq58-crwm-qgwh: Unspecified vulnerability in Oracle Java SE 7u85 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Librar
ghsa_unreviewed·2022-05-14
CVE-2015-4871 [MEDIUM] GHSA-gq58-crwm-qgwh: Unspecified vulnerability in Oracle Java SE 7u85 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Librar
Unspecified vulnerability in Oracle Java SE 7u85 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.
OSV
CVE-2015-4871: Unspecified vulnerability in Oracle Java SE 7u85 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Librar
osv·2015-10-21·CVSS 5.8
CVE-2015-4871 [MEDIUM] CVE-2015-4871: Unspecified vulnerability in Oracle Java SE 7u85 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Librar
Unspecified vulnerability in Oracle Java SE 7u85 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.
Ubuntu
OpenJDK 7 vulnerability
vendor_ubuntu·2015-11-25
CVE-2015-4871 OpenJDK 7 vulnerability
Title: OpenJDK 7 vulnerability
Summary: A security issue was fixed in OpenJDK 7.
It was discovered that rebinding of the receiver of a
DirectMethodHandle may allow a protected method to be accessed. Am
attacker could use this to expose sensitive information or possibly
execute arbitrary code.
Instructions: After a standard system update you need to restart any Java
applications or applets to make all the necessary changes.
Red Hat
OpenJDK: protected methods can be used as interface methods via DirectMethodHandle (Libraries)
vendor_redhat·2015-10-20·CVSS 5.8
CVE-2015-4871 [MEDIUM] OpenJDK: protected methods can be used as interface methods via DirectMethodHandle (Libraries)
OpenJDK: protected methods can be used as interface methods via DirectMethodHandle (Libraries)
Unspecified vulnerability in Oracle Java SE 7u85 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.8.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 7) - Not affected
Package: java-1.8.0-openjdk (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1927.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2506.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2507.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2509.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0053.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0054.htmlhttp://www.debian.org/security/2015/dsa-3381http://www.debian.org/security/2015/dsa-3401http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/77238http://www.securitytracker.com/id/1033884http://www.ubuntu.com/usn/USN-2818-1https://access.redhat.com/errata/RHSA-2016:1430https://security.gentoo.org/glsa/201603-11https://security.gentoo.org/glsa/201603-14http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1927.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2506.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2507.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2509.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0053.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0054.htmlhttp://www.debian.org/security/2015/dsa-3381http://www.debian.org/security/2015/dsa-3401http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/77238http://www.securitytracker.com/id/1033884http://www.ubuntu.com/usn/USN-2818-1https://access.redhat.com/errata/RHSA-2016:1430https://security.gentoo.org/glsa/201603-11https://security.gentoo.org/glsa/201603-14
2015-10-21
Published