cbcvebase.
CVE-2015-4902
published 2015-10-22

CVE-2015-4902: Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

PriorityP276medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
13.35%
96.0th percentile
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
debianopenjdk-8
opensuseleap
opensuseopensuse
oraclejdk
oraclejdk
oraclejdk
oraclejre
oraclejre
oraclejre
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus_compute_node
redhatenterprise_linux_eus_compute_node
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_ibm_z_systems_eus

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2015-4902 has been observed exploited in the wild to bypass Java click-to-play protection in the browser; monitor for exploitation attempts targeting Java Deployment component in versions 6u101, 7u85, and 8u60 or earlier
  • ·Vulnerability affects Oracle Java SE 6u101, 7u85, and 8u60 via the Deployment component; fixed in 6u105, 7u91, and 8u65. Ensure Java installations are updated to at least these versions.

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vulncheck5.3MEDIUM
cisa5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.