CVE-2015-0412

Published Jan 21, 2015

Last updated 18 days ago

Overview

Description
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS.
Source
secalert_us@oracle.com
NVD status
Modified
Products
ubuntu_linux, debian_linux, suse_linux_enterprise_desktop, suse_linux_enterprise_server, opensuse, enterprise_linux, jdk, jre

Risk scores

CVSS 2.0

Type
Primary
Base score
7.2
Impact score
10
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Evaluator

Comment
As per Oracle: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets.
Impact
-
Solution
-

Configurations

References

Sources include official advisories and independent security research.