Junglewise Threat Intelligence

CVE-2015-4902: Oracle Java SE Integrity Check Vulnerability

CVE-2015-4902 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2022-03-03

Technologies: Oracle Java SE, Oracle JRockit. Vendors: Oracle.

Executive brief

An unspecified vulnerability in Oracle Java SE's Deployment component allows remote attackers to impact system integrity. The flaw affects versions 6u101, 7u85, and 8u60 and is known to have been exploited in the wild.

Affected products

  • Oracle Java SE 6u101, 7u85, 8u60

Timeline

  • 2015-10-20: patched: Oracle Critical Patch Update October 2015
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats