CVE-2015-4902
5.3
MEDIUM
CVSS 3.1
EPSS 13.6% · 96th pctCISA KEV · Exploited in the wild
2015-10-21•Updated 2025-10-21•KEV 2022-03-03
CISA Known Exploited Vulnerabilities
Oracle Java SE Integrity Check Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Added to KEV
2022-03-03
Remediation due
2022-03-24
Required action
Apply updates per vendor instructions.
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2015-4902
Description
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
Severity
CVSS 3.1 · CISA5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NSSVC · CISA-ADP
Exploitationactive
Automatableyes
Technical impactpartial
Affected Products
| Vendor | Product | Affected versions |
|---|---|---|
| - | - | n/a |
References
22 LinksVendor advisories
- SUSE-SU-2015:2182
- openSUSE-SU-2015:1905
- SUSE-SU-2015:2192
- RHSA-2015:2507
- RHSA-2015:1928
- RHSA-2016:1430
- RHSA-2015:2506
- RHSA-2015:2509
- SUSE-SU-2015:2166
- openSUSE-SU-2016:0270
- GLSA-201603-11
- RHSA-2015:2518
- SUSE-SU-2015:2216
- RHSA-2015:1927
- SUSE-SU-2015:2268
- SUSE-SU-2015:2168
- RHSA-2015:1926
- RHSA-2015:2508
- SUSE-SU-2016:0113
Record Details
Published
2015-10-21
Last updated
2025-10-21
Assigner (CNA)
oracle
Credited to
-
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.