CVE-2015-0192
Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.98%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.98% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- ibm/java · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux workstation · suse/linux enterprise server · suse/linux enterprise software development kit
- Source
- psirt@us.ibm.com
References
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1006.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1007.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1020.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1021.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1091.htmlThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV70682Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV70683Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21883640Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1006.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1007.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1020.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1021.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1091.htmlThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV70682Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV70683Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21883640Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.