CVE-2015-4902
published 2015-10-22CVE-2015-4902: Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
PriorityP276medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
13.35%
96.0th percentile
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | — | — |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus_compute_node | — | — |
| redhat | enterprise_linux_eus_compute_node | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2015-4902 has been observed exploited in the wild to bypass Java click-to-play protection in the browser; monitor for exploitation attempts targeting Java Deployment component in versions 6u101, 7u85, and 8u60 or earlier ↗
- ·Vulnerability affects Oracle Java SE 6u101, 7u85, and 8u60 via the Deployment component; fixed in 6u105, 7u91, and 8u65. Ensure Java installations are updated to at least these versions. ↗
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vulncheck5.3MEDIUM
cisa5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Oracle Java SE Integrity Check Vulnerability
cisa·2022-03-03·CVSS 5.3
CVE-2015-4902 [MEDIUM] Oracle Java SE Integrity Check Vulnerability
Vulnerability: Oracle Java SE Integrity Check Vulnerability
Affected: Oracle Java SE
Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-4902
Remediation Due Date: 2022-03-24
Red Hat
JDK: unspecified vulnerability fixed in 6u105, 7u91 and 8u65 (Deployment)
vendor_redhat·2015-10-20·CVSS 5.3
CVE-2015-4902 [MEDIUM] JDK: unspecified vulnerability fixed in 6u105, 7u91 and 8u65 (Deployment)
JDK: unspecified vulnerability fixed in 6u105, 7u91 and 8u65 (Deployment)
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
Debian
CVE-2015-4902: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote ...
vendor_debian·2015·CVSS 5.3
CVE-2015-4902 [MEDIUM] CVE-2015-4902: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote ...
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
Scope: local
sid: resolved
VulDB
Oracle Java SE 6u101/7u85/8u60 Deployment denial of service (EUVD-2015-4919 / Nessus ID 86731)
vuldb·2026-04-22·CVSS 5.3
CVE-2015-4902 [MEDIUM] Oracle Java SE 6u101/7u85/8u60 Deployment denial of service (EUVD-2015-4919 / Nessus ID 86731)
A vulnerability was found in Oracle Java SE 6u101/7u85/8u60. It has been classified as critical. This issue affects some unknown processing of the component Deployment. This manipulation causes denial of service.
This vulnerability appears as CVE-2015-4902. The attack may be initiated remotely. In addition, an exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-69xw-2hhx-gvfg: Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deploymen
ghsa_unreviewed·2022-05-13
CVE-2015-4902 [MEDIUM] CWE-284 GHSA-69xw-2hhx-gvfg: Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deploymen
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
VulnCheck
Oracle Java SE Integrity Check Vulnerability
vulncheck·2015·CVSS 5.3
CVE-2015-4902 [MEDIUM] Oracle Java SE Integrity Check Vulnerability
Oracle Java SE Integrity Check Vulnerability
Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.
Affected: Oracle Java SE
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.recordedfuture.com/russian-apt-toolkits; https://marcoramilli.com/2019/12/05/apt28-attacks-evolution/; https://www.tenable.com/blog/daisy-chaining-how-vulnerabilities-can-be-greater-than-the-sum-of-their-parts; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.logpoint.com/wp-content/uploads/2024/06/logpoint-etpr-forest-blizzard.pdf
Remediation Due: 2022-03-24
No detection rules found.
No public exploits indexed.
Tenable
Daisy Chaining: How Vulnerabilities Can Be Greater Than the Sum of Their Parts
blogs_tenable·2021-01-21
Daisy Chaining: How Vulnerabilities Can Be Greater Than the Sum of Their Parts
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Oracle Critical Patch Update October 2015 | Qualys
blogs_qualys·2015-10-21·CVSS 5.3
CVE-2015-4902 [MEDIUM] Oracle Critical Patch Update October 2015 | Qualys
Oracle published their quarterly critical patch update October 2015 addressing 154 vulnerabilities distributed across 50+ different products. We will give you our read on the update and help with your prioritization.
1. Update for Oracle Java: The newest release for Java v8 is update 65. Oracle fixed 25 vulnerabilities and 24 can be attacked through remote channels There are seven vulnerabilities with the maximum CVSS score of 10. One of the lower severity vulnerabilities, CVE-2015-4902, has been used in the wild to bypass Java click-to-play protection in the browser. Trend Micro has published a blog post with the technical details and how the vulnerability was detected.
Oracle still maintains Java v6 and v7, but only for customers with a maintenance contract. IT departments can use the
Threat Intel
APT28 (APT28, IRON TWILIGHT, SNAKEMACKEREL)
threat_intel
APT28 (APT28, IRON TWILIGHT, SNAKEMACKEREL)
# Threat Actor Profile: APT28
ATT&CK ID: G0007
Also known as: APT28, IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch
Suspected origin: Russia
## Overview
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citation: FireEye APT28)(Citation: SecureWorks TG-412
Bugzilla
CVE-2015-4902 Oracle JDK: unspecified vulnerability fixed in 6u105, 7u91 and 8u65 (Deployment)
bugzilla·2015-10-21·CVSS 5.3
CVE-2015-4902 [MEDIUM] CVE-2015-4902 Oracle JDK: unspecified vulnerability fixed in 6u105, 7u91 and 8u65 (Deployment)
CVE-2015-4902 Oracle JDK: unspecified vulnerability fixed in 6u105, 7u91 and 8u65 (Deployment)
Oracle Java SE 6u105, 7u91 and 8u65 fixes an unspecified vulnerability in the Deployment component (CVE-2015-4902). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:N/I:P/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 5
Oracle Java for Red Hat Enterprise Linux 6
Via RHSA-2015:1928 https://rhn.redhat.com/errata/RHSA-2015-1928.html
---
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Ente
arXiv
Attack Techniques and Threat Identification for Vulnerabilities
arxiv_fulltext·2022-06-22
Attack Techniques and Threat Identification for Vulnerabilities
Attack Techniques and Threat Identification for Vulnerabilities
Constantin Adam
Muhammed Fatih Bulut
Daby Sow
cmadam, mfbulut, [email protected]
IBM T.J. Watson Research Center
Yorktown Heights
NY
USA
Steven Ocepek
Chris Bedell
steve.ocepek, [email protected]
IBM Security X-Force Red
USA
Lilian Ngweta
[email protected]
Rensselaer Polytechnic Institute
Troy
NY
USA
Adam and Bulut, et al.
## Abstract
Modern organizations struggle with what is often considered an insurmountable number of vulnerabilities that are discovered and reported by their network and application vulnerability scanners. Therefore, prioritization and focus become critical, to spend their limited time on the highest risk vulnerabilities. In doing this, it is important for these organizations not only to
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1926.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1927.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1928.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2506.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2507.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2508.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2509.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2518.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securityfocus.com/bid/77241http://www.securitytracker.com/id/1033884https://access.redhat.com/errata/RHSA-2016:1430https://security.gentoo.org/glsa/201603-11http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1926.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1927.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1928.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2506.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2507.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2508.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2509.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2518.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securityfocus.com/bid/77241http://www.securitytracker.com/id/1033884https://access.redhat.com/errata/RHSA-2016:1430https://security.gentoo.org/glsa/201603-11https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-4902
2015-10-22
Published
2022-03-03
Added to CISA KEV
Exploited in the wild