⚠ Actively exploited
Added to CISA KEV on 2022-03-03. Federal agencies required to patch by 2022-03-24. Required action: Apply updates per vendor instructions..

CVE-2015-4902

Severity
5.3MEDIUM
EPSS
7.7%
top 8.09%
CISA KEV
KEV
Added 2022-03-03
Due 2022-03-24
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedOct 22
KEV addedMar 3
KEV dueMar 24
Latest updateMay 13
CISA Required Action: Apply updates per vendor instructions.

Description

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages12 packages

NVDoracle/jdk1.6.0, 1.7.0, 1.8.0+2
NVDoracle/jre1.6.0, 1.7.0, 1.8.0+2
NVDopensuse/leap42.1
NVDredhat/satellite5.6, 5.7+1

Also affects: Enterprise Linux 6.7, 7.2, 7.3, 7.4, 7.5, 5.0, 6.0, 7.0, 5.0_ppc, 6.0_ppc64, 7.0_ppc64, 6.7_ppc64, 7.2_ppc64, 7.3_ppc64, 7.4_ppc64, 7.5_ppc64

Patches

🔴Vulnerability Details

3
GHSA
GHSA-69xw-2hhx-gvfg: Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deploymen2022-05-13
CVEList
CVE-2015-4902: Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deploymen2015-10-21
VulnCheck
Oracle Java SE Integrity Check Vulnerability2015

📋Vendor Advisories

3
CISA
Oracle Java SE Integrity Check Vulnerability2022-03-03
Red Hat
JDK: unspecified vulnerability fixed in 6u105, 7u91 and 8u65 (Deployment)2015-10-20
Debian
CVE-2015-4902: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote ...2015

🕵️Threat Intelligence

1
Qualys
Oracle Critical Patch Update October 2015 | Qualys2015-10-21

💬Community

1
Bugzilla
CVE-2015-4902 Oracle JDK: unspecified vulnerability fixed in 6u105, 7u91 and 8u65 (Deployment)2015-10-21