National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2015-4893 Detail

Description

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60; Java SE Embedded 8u51; and JRockit R28.3.7 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than CVE-2015-4803 and CVE-2015-4911.

Source:  MITRE      Last Modified:  10/21/2015

Evaluator Description

Per LINK: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service.

Quick Info

CVE Dictionary Entry:
CVE-2015-4893
Original release date:
10/21/2015
Last revised:
12/23/2016
Source:
US-CERT/NIST

Impact

CVSS Severity (version 2.0):
CVSS v2 Base Score:
5.0 MEDIUM
Vector:
(AV:N/AC:L/Au:N/C:N/I:N/A:P) (legend)
Impact Subscore:
2.9
Exploitability Subscore:
10.0
CVSS Version 2 Metrics:
Access Vector:
Network exploitable
Access Complexity:
Low
Authentication:
Not required to exploit
Impact Type:
Allows disruption of service

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource Type Source Name
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00000.html External Source SUSE SUSE-SU-2015:1874
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00001.html External Source SUSE SUSE-SU-2015:1875
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00008.html External Source SUSE openSUSE-SU-2015:1902
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00009.html External Source SUSE openSUSE-SU-2015:1905
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00010.html External Source SUSE openSUSE-SU-2015:1906
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00019.html External Source SUSE openSUSE-SU-2015:1971
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html External Source SUSE SUSE-SU-2015:2166
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.html External Source SUSE SUSE-SU-2015:2168
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.html External Source SUSE SUSE-SU-2015:2182
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html External Source SUSE SUSE-SU-2015:2192
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.html External Source SUSE SUSE-SU-2015:2216
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.html External Source SUSE SUSE-SU-2015:2268
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.html External Source SUSE SUSE-SU-2016:0113
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html External Source SUSE openSUSE-SU-2016:0270
http://rhn.redhat.com/errata/RHSA-2015-1919.html External Source REDHAT RHSA-2015:1919
http://rhn.redhat.com/errata/RHSA-2015-1920.html External Source REDHAT RHSA-2015:1920
http://rhn.redhat.com/errata/RHSA-2015-1921.html External Source REDHAT RHSA-2015:1921
http://rhn.redhat.com/errata/RHSA-2015-1926.html External Source REDHAT RHSA-2015:1926
http://rhn.redhat.com/errata/RHSA-2015-1927.html External Source REDHAT RHSA-2015:1927
http://rhn.redhat.com/errata/RHSA-2015-1928.html External Source REDHAT RHSA-2015:1928
http://rhn.redhat.com/errata/RHSA-2015-2506.html External Source REDHAT RHSA-2015:2506
http://rhn.redhat.com/errata/RHSA-2015-2507.html External Source REDHAT RHSA-2015:2507
http://rhn.redhat.com/errata/RHSA-2015-2508.html External Source REDHAT RHSA-2015:2508
http://rhn.redhat.com/errata/RHSA-2015-2509.html External Source REDHAT RHSA-2015:2509
http://www.debian.org/security/2015/dsa-3381 External Source DEBIAN DSA-3381
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html Patch; Vendor Advisory External Source CONFIRM http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html External Source CONFIRM http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
http://www.securityfocus.com/bid/77207 External Source BID 77207
http://www.securitytracker.com/id/1033884 External Source SECTRACK 1033884
http://www.ubuntu.com/usn/USN-2784-1 External Source UBUNTU USN-2784-1
http://www.ubuntu.com/usn/USN-2827-1 External Source UBUNTU USN-2827-1
https://access.redhat.com/errata/RHSA-2016:1430 External Source REDHAT RHSA-2016:1430
https://kc.mcafee.com/corporate/index?page=content&id=SB10141 External Source CONFIRM https://kc.mcafee.com/corporate/index?page=content&id=SB10141
https://security.gentoo.org/glsa/201603-11 External Source GENTOO GLSA-201603-11
https://security.gentoo.org/glsa/201603-14 External Source GENTOO GLSA-201603-14

Technical Details

Vulnerability Type (View All)

Change History 12 change records found - show changes