CVE-2015-0400

Published Jan 21, 2015

Last updated 18 days ago

Overview

Description
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries.
Source
secalert_us@oracle.com
NVD status
Modified
Products
ubuntu_linux, suse_linux_enterprise_desktop, suse_linux_enterprise_server, opensuse, jdk, jre

Risk scores

CVSS 2.0

Type
Primary
Base score
5
Impact score
2.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Evaluator

Comment
As per Oracle: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
Impact
-
Solution
-

Configurations

References

Sources include official advisories and independent security research.