CVE-2015-0192
Last modified
CVE-2015-0192 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.. EPSS estimates a 4.54% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ibm | Java | >= 5.0.0.0, < 5.0.16.10 | — |
| Ibm | Java | >= 6.0.0.0, <= 6.0.16.4 | — |
| Ibm | Java | >= 6.1.0.0, < 6.1.8.4 | — |
| Ibm | Java | >= 7.0.0.0, <= 7.0.9 | — |
| Ibm | Java | >= 7.1.0.0, < 7.1.2.11 | — |
| Ibm | Java | >= 8.0, < 8.0.1.0 | — |
| Redhat | Enterprise Linux Desktop | 5.0 | — |
| Redhat | Enterprise Linux Desktop | 6.0 | — |
| Redhat | Enterprise Linux Desktop | 7.0 | — |
| Redhat | Enterprise Linux Server | 5.0 | — |
| Redhat | Enterprise Linux Server | 6.0 | — |
| Redhat | Enterprise Linux Server | 7.0 | — |
| Redhat | Enterprise Linux Server Aus | 6.6 | — |
| Redhat | Enterprise Linux Server Eus | 6.6 | — |
| Redhat | Enterprise Linux Server Eus | 7.1 | — |
| Redhat | Enterprise Linux Server Eus | 7.2 | — |
| Redhat | Enterprise Linux Server Eus | 7.3 | — |
| Redhat | Enterprise Linux Server Eus | 7.4 | — |
| Redhat | Enterprise Linux Server Eus | 7.5 | — |
| Redhat | Enterprise Linux Workstation | 5.0 | — |
| Redhat | Enterprise Linux Workstation | 6.0 | — |
| Redhat | Enterprise Linux Workstation | 7.0 | — |
| Suse | Linux Enterprise Server | 10 | Sp4 |
| Suse | Linux Enterprise Server | 11 | Sp1 |
| Suse | Linux Enterprise Server | 12 | — |
| Suse | Linux Enterprise Software Development Kit | 12 | — |
References
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1006.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1007.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1020.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1021.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1091.htmlThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV70682Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV70683Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21883640Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1006.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1007.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1020.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1021.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1091.htmlThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV70682Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV70683Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21883640Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0192?
How severe is CVE-2015-0192?
How do I fix CVE-2015-0192?
Are you affected by CVE-2015-0192?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
