CVE-2015-4868

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Unspecified vulnerability in Oracle Java SE 8u60 and Java SE Embedded 8u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

References

http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00009.html

http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html

http://rhn.redhat.com/errata/RHSA-2015-1919.html

http://rhn.redhat.com/errata/RHSA-2015-1926.html

http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html

http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html

http://www.securityfocus.com/bid/77225

http://www.securitytracker.com/id/1033884

http://www.ubuntu.com/usn/USN-2784-1

https://kc.mcafee.com/corporate/index?page=content&id=SB10141

https://security.gentoo.org/glsa/201603-11

Details

Source: MITRE

Published: 2015-10-21

Updated: 2020-09-08

Risk Information

CVSS v2

Base Score: 7.6

Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 4.9

Severity: HIGH

Tenable Plugins

View all (15 total)

IDNameProductFamilySeverity
700652Oracle Java SE 6 < Update 105 / 7 < Update 91 / 8 < Update 65 Multiple Vulnerabilities (October 2015 CPU)Nessus Network MonitorWeb Clients
critical
9352Oracle Java SE 6 < Update 105 / 7 < Update 91 / 8 < Update 65 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
critical
89904GLSA-201603-11 : Oracle JRE/JDK: Multiple vulnerabilities (Logjam)NessusGentoo Local Security Checks
low
88537openSUSE Security Update : java-1_8_0-openjdk (openSUSE-2016-106) (SLOTH)NessusSuSE Local Security Checks
high
87386FreeBSD : java -- multiple vulnerabilities (a5934ba8-a376-11e5-85e9-14dae9d210b8)NessusFreeBSD Local Security Checks
critical
86731openSUSE Security Update : java-1_8_0-openjdk (openSUSE-2015-696)NessusSuSE Local Security Checks
critical
86650Ubuntu 14.04 LTS / 15.04 / 15.10 : openjdk-7 vulnerabilities (USN-2784-1)NessusUbuntu Local Security Checks
critical
86637Amazon Linux AMI : java-1.8.0-openjdk (ALAS-2015-606)NessusAmazon Linux Local Security Checks
critical
86560RHEL 6 / 7 : java-1.8.0-oracle (RHSA-2015:1926)NessusRed Hat Local Security Checks
critical
86543Oracle Java SE Multiple Vulnerabilities (October 2015 CPU) (Unix)NessusMisc.
critical
86542Oracle Java SE Multiple Vulnerabilities (October 2015 CPU)NessusWindows
critical
86529Scientific Linux Security Update : java-1.8.0-openjdk on SL6.x, SL7.x i386/x86_64 (20151021)NessusScientific Linux Local Security Checks
critical
86524RHEL 6 / 7 : java-1.8.0-openjdk (RHSA-2015:1919)NessusRed Hat Local Security Checks
critical
86520Oracle Linux 6 / 7 : java-1.8.0-openjdk (ELSA-2015-1919)NessusOracle Linux Local Security Checks
critical
86516CentOS 6 / 7 : java-1.8.0-openjdk (CESA-2015:1919)NessusCentOS Local Security Checks
critical