CVE-2015-0383

MEDIUM

Description

Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related to Hotspot.

References

http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04583581

http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158088.html

http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158791.html

http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158810.html

http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00024.html

http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00018.html

http://marc.info/?l=bugtraq&m=142496355704097&w=2

http://marc.info/?l=bugtraq&m=142607790919348&w=2

http://rhn.redhat.com/errata/RHSA-2015-0068.html

http://rhn.redhat.com/errata/RHSA-2015-0079.html

http://rhn.redhat.com/errata/RHSA-2015-0080.html

http://rhn.redhat.com/errata/RHSA-2015-0085.html

http://rhn.redhat.com/errata/RHSA-2015-0086.html

http://www.debian.org/security/2015/dsa-3144

http://www.debian.org/security/2015/dsa-3147

http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html

http://www.securityfocus.com/bid/72155

http://www.securitytracker.com/id/1031580

http://www.ubuntu.com/usn/USN-2486-1

http://www.ubuntu.com/usn/USN-2487-1

http://www.vmware.com/security/advisories/VMSA-2015-0003.html

https://exchange.xforce.ibmcloud.com/vulnerabilities/100148

https://security.gentoo.org/glsa/201507-14

https://security.gentoo.org/glsa/201603-14

Details

Source: MITRE

Published: 2015-01-21

Updated: 2020-09-08

Risk Information

CVSS v2.0

Base Score: 5.4

Vector: AV:L/AC:M/Au:N/C:N/I:P/A:C

Impact Score: 7.8

Exploitability Score: 3.4

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:*

cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*

cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*

cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*

cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*

cpe:2.3:o:novell:suse_linux_enterprise_desktop:11.0:sp3:*:*:*:*:*:*

cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:*:*:*:*:*:*:*

cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

Configuration 2

OR

cpe:2.3:a:oracle:jdk:1.5.0:update_75:*:*:*:*:*:*

cpe:2.3:a:oracle:jdk:1.6.0:update_85:*:*:*:*:*:*

cpe:2.3:a:oracle:jdk:1.7.0:update71:*:*:*:*:*:*

cpe:2.3:a:oracle:jdk:1.7.0:update72:*:*:*:*:*:*

cpe:2.3:a:oracle:jdk:1.8.0:update25:*:*:*:*:*:*

cpe:2.3:a:oracle:jdk:1.8.0:update6:*:*:*:*:*:*

cpe:2.3:a:oracle:jre:1.5.0:update_75:*:*:*:*:*:*

cpe:2.3:a:oracle:jre:1.6.0:update_85:*:*:*:*:*:*

cpe:2.3:a:oracle:jre:1.7.0:update_71:*:*:*:*:*:*

cpe:2.3:a:oracle:jre:1.7.0:update_72:*:*:*:*:*:*

cpe:2.3:a:oracle:jre:1.8.0:update_25:*:*:*:*:*:*

cpe:2.3:a:oracle:jre:1.8.0:update_6:*:*:*:*:*:*

Configuration 3

OR

cpe:2.3:a:oracle:jrockit:r27.8.4:*:*:*:*:*:*:*

cpe:2.3:a:oracle:jrockit:r28.3.4:*:*:*:*:*:*:*

Tenable Plugins

View all (51 total)

IDNameProductFamilySeverity
700649Oracle Java SE 5 < Update 81 / 6 < Update 91 / 7 < Update 75 / 8 < Update 31 Multiple Vulnerabilities (January 2015 CPU) (POODLE)Nessus Network MonitorWeb Clients
critical
89907GLSA-201603-14 : IcedTea: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
84931Amazon Linux AMI : java-1.8.0-openjdk (ALAS-2015-571) (Bar Mitzvah) (Logjam)NessusAmazon Linux Local Security Checks
critical
84793Scientific Linux Security Update : java-1.8.0-openjdk on SL6.x, SL7.x i386/x86_64 (20150715) (Bar Mitzvah) (Logjam)NessusScientific Linux Local Security Checks
critical
84719GLSA-201507-14 : Oracle JRE/JDK: Multiple vulnerabilities (POODLE)NessusGentoo Local Security Checks
critical
83893Fedora 20 : java-1.8.0-openjdk-1.8.0.45-38.b14.fc20 (2015-8251)NessusFedora Local Security Checks
medium
83830Fedora 22 : java-1.8.0-openjdk-1.8.0.45-38.b14.fc22 (2015-8226)NessusFedora Local Security Checks
medium
83699SUSE SLED12 / SLES12 Security Update : java-1_7_0-openjdk (SUSE-SU-2015:0503-1) (POODLE)NessusSuSE Local Security Checks
critical
83507Fedora 21 : java-1.8.0-openjdk-1.8.0.45-38.b14.fc21 (2015-8264)NessusFedora Local Security Checks
medium
83186VMware vCenter Server Multiple Java Vulnerabilities (VMSA-2015-0003) (POODLE)NessusMisc.
critical
82899VMware vCenter Chargeback Manager Multiple Java Vulnerabilities (VMSA-2015-0003) (POODLE)NessusWindows
critical
82742VMware Workspace Portal Multiple Java Vulnerabilities (VMSA-2015-0003) (POODLE)NessusMisc.
critical
82741VMware Horizon View Multiple Vulnerabilities (VMSA-2015-0003) (VMSA-2015-0008) (POODLE)NessusWindows
critical
82707VMware vCenter Operations Management Windows JRE Update 1.7.0_76-b13 (VMSA-2015-0003) (POODLE)NessusMisc.
critical
82706VMware vCenter Operations Management vApp JRE Update 1.7.0_76-b13 (VMSA-2015-0003) (POODLE)NessusMisc.
critical
82705VMware vCenter Operations Management Linux JRE Update 1.7.0_76-b13 (VMSA-2015-0003) (POODLE)NessusMisc.
critical
82684Mandriva Linux Security Advisory : java-1.8.0-openjdk (MDVSA-2015:198)NessusMandriva Local Security Checks
critical
82140Debian DLA-157-1 : openjdk-6 security update (POODLE)NessusDebian Local Security Checks
critical
81419SuSE 11.3 Security Update : java-1_7_0-openjdk (SAT Patch Number 10286)NessusSuSE Local Security Checks
critical
81326Amazon Linux AMI : java-1.6.0-openjdk (ALAS-2015-480) (POODLE)NessusAmazon Linux Local Security Checks
critical
8897Oracle Java SE 5 < Update 76 / 6 < Update 86 / 7 < Update 73 / 8 < Update 26 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
81233Mandriva Linux Security Advisory : java-1.7.0-openjdk (MDVSA-2015:033)NessusMandriva Local Security Checks
critical
81141openSUSE Security Update : java-1_7_0-openjdk (openSUSE-SU-2015:0190-1) (POODLE)NessusSuSE Local Security Checks
critical
81111Debian DSA-3147-1 : openjdk-6 - security update (POODLE)NessusDebian Local Security Checks
critical
81090Debian DSA-3144-1 : openjdk-7 - security update (POODLE)NessusDebian Local Security Checks
critical
81045Ubuntu 14.04 LTS / 14.10 : openjdk-7 vulnerabilities (USN-2487-1) (POODLE)NessusUbuntu Local Security Checks
critical
81043Ubuntu 10.04 LTS / 12.04 LTS : openjdk-6 vulnerabilities (USN-2486-1) (POODLE)NessusUbuntu Local Security Checks
critical
81015Scientific Linux Security Update : java-1.6.0-openjdk on SL5.x, SL6.x, SL7.x i386/x86_64 (20150126) (POODLE)NessusScientific Linux Local Security Checks
critical
81014RHEL 5 / 6 / 7 : java-1.6.0-sun (RHSA-2015:0086) (POODLE)NessusRed Hat Local Security Checks
critical
81013RHEL 5 / 6 / 7 : java-1.6.0-openjdk (RHSA-2015:0085) (POODLE)NessusRed Hat Local Security Checks
critical
81011Oracle Linux 5 / 6 / 7 : java-1.6.0-openjdk (ELSA-2015-0085) (POODLE)NessusOracle Linux Local Security Checks
critical
81005CentOS 5 / 6 / 7 : java-1.6.0-openjdk (CESA-2015:0085) (POODLE)NessusCentOS Local Security Checks
critical
80932RHEL 6 : java-1.8.0-oracle (RHSA-2015:0080) (POODLE)NessusRed Hat Local Security Checks
critical
80931RHEL 5 / 6 / 7 : java-1.7.0-oracle (RHSA-2015:0079) (POODLE)NessusRed Hat Local Security Checks
critical
80922Amazon Linux AMI : java-1.8.0-openjdk (ALAS-2015-472) (POODLE)NessusAmazon Linux Local Security Checks
critical
80921Amazon Linux AMI : java-1.7.0-openjdk (ALAS-2015-471) (POODLE)NessusAmazon Linux Local Security Checks
critical
80908Oracle Java SE Multiple Vulnerabilities (January 2015 CPU) (POODLE)NessusWindows
critical
80907Oracle Java SE Multiple Vulnerabilities (January 2015 CPU) (Unix) (POODLE)NessusMisc.
critical
80904Scientific Linux Security Update : java-1.8.0-openjdk on SL6.x i386/x86_64 (20150121) (POODLE)NessusScientific Linux Local Security Checks
critical
80903Scientific Linux Security Update : java-1.7.0-openjdk on SL6.x, SL7.x i386/x86_64 (20150121) (POODLE)NessusScientific Linux Local Security Checks
critical
80902Scientific Linux Security Update : java-1.7.0-openjdk on SL5.x i386/x86_64 (20150121) (POODLE)NessusScientific Linux Local Security Checks
critical
80901Oracle Linux 6 : java-1.8.0-openjdk (ELSA-2015-0069) (POODLE)NessusOracle Linux Local Security Checks
critical
80900Oracle Linux 5 : java-1.7.0-openjdk (ELSA-2015-0068) (POODLE)NessusOracle Linux Local Security Checks
critical
80899Oracle Linux 6 / 7 : java-1.7.0-openjdk (ELSA-2015-0067) (POODLE)NessusOracle Linux Local Security Checks
critical
80890Oracle JRockit R27.8.4 / R28.3.4 Multiple Vulnerabilities (January 2015 CPU) (POODLE)NessusWindows
medium
80882RHEL 6 : java-1.8.0-openjdk (RHSA-2015:0069) (POODLE)NessusRed Hat Local Security Checks
critical
80881RHEL 5 : java-1.7.0-openjdk (RHSA-2015:0068) (POODLE)NessusRed Hat Local Security Checks
critical
80880RHEL 6 / 7 : java-1.7.0-openjdk (RHSA-2015:0067) (POODLE)NessusRed Hat Local Security Checks
critical
80870CentOS 6 : java-1.8.0-openjdk (CESA-2015:0069) (POODLE)NessusCentOS Local Security Checks
critical
80869CentOS 5 : java-1.7.0-openjdk (CESA-2015:0068) (POODLE)NessusCentOS Local Security Checks
critical
80868CentOS 6 / 7 : java-1.7.0-openjdk (CESA-2015:0067) (POODLE)NessusCentOS Local Security Checks
critical