CVE-2015-4902 Details
Description
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
A vulnerability in the Oracle Java SE Deployment component has been identified, allowing remote attackers to modify data. This issue affects multiple versions of Oracle Java SE, including 6u101, 7u85, and 8u60. The vulnerability arises from unspecified vectors related to the deployment component, which is responsible for managing the execution of Java applications in a web environment.
Users can upgrade to the latest version of Oracle Java SE to address this vulnerability. Instructions for applying this update can be found in the Oracle Critical Patch Update October 2015 Availability Document, available on the Oracle Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Oracle Java SE Integrity Check Vulnerability | Mar 3, 2022 | Mar 24, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| oracle jdk | 1.6.0 update101 1.7.0 update85 1.8.0 update60 |
CPE
Remediation
| |
| oracle jre | 1.6.0 update101 1.7.0 update85 1.8.0 update60 |
CPE
Remediation
| |
| redhat satellite | 5.6 5.7 |
CPE
Remediation
| |
| redhat enterprise linux desktop | 5.0 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux eus | 6.7 7.2 7.3 7.4 7.5 |
CPE
Remediation
| |
| redhat enterprise linux eus compute node | 7.2 7.3 |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems | 5.0_s390x 6.0_s390x 7.0_s390x |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems eus | 6.7_s390x 7.2_s390x 7.3_s390x 7.4_s390x 7.5_s390x |
CPE
Remediation
| |
| redhat enterprise linux for power big endian | 5.0_ppc 6.0_ppc64 7.0_ppc64 |
CPE
Remediation
| |
| redhat enterprise linux for power big endian eus | 6.7_ppc64 7.2_ppc64 7.3_ppc64 7.4_ppc64 7.5_ppc64 |
CPE
Remediation
| |
| redhat enterprise linux for power little endian | 7.0_ppc64le |
CPE
Remediation
| |
| redhat enterprise linux for power little endian eus | 7.2_ppc64le 7.3_ppc64le 7.4_ppc64le 7.5_ppc64le |
CPE
Remediation
| |
| redhat enterprise linux for scientific computing | 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux server | 5.0 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux server from rhui | 5.0 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux workstation | 5.0 6.0 7.0 |
CPE
Remediation
| |
| suse linux enterprise module for legacy | 12 |
CPE
Remediation
| |
| opensuse leap | 42.1 |
CPE
Remediation
| |
| opensuse opensuse | 13.2 |
CPE
Remediation
| |
| suse linux enterprise server | 10 sp4 11 sp2 11 sp3 11 sp4 12 - 12 sp1 |
CPE
Remediation
| |
| suse linux enterprise software development kit | 11 sp3 11 sp4 12 - 12 sp1 |
CPE
Remediation
| |
Change History
23 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 13, 2025 | Modified Analysis | [email protected] |
| Feb 10, 2025 | CVE Modified | CISA-ADP |
| Jan 28, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 24, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| May 13, 2022 | CPE Deprecation Remap | [email protected] |
| Sep 8, 2020 | CPE Deprecation Remap | [email protected] |
| Dec 24, 2016 | CVE Modified | [email protected] |
| Dec 7, 2016 | CVE Modified | [email protected] |
| Dec 3, 2016 | CVE Modified | [email protected] |
| Nov 28, 2016 | CVE Modified | [email protected] |
| Apr 11, 2016 | Modified Analysis | [email protected] |
| Apr 7, 2016 | CVE Modified | [email protected] |
| Oct 22, 2015 | Modified Analysis | [email protected] |
| Oct 22, 2015 | Initial Analysis | [email protected] |