ZeroHour

CVE-2015-2590

KEVmass

Remote Code Execution Vulnerability in Oracle Java SE and Java SE Embedded

CISA: Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability

CVSS
EPSS
25%p98
Published
KEV added
AI analysis

CVE-2015-2590 is an unspecified vulnerability in Oracle's Java Runtime Environment (Java SE, and Java SE Embedded per CISA's naming) that allows a remote attacker to achieve remote code execution. Oracle did not publish technical details, so the exact trigger is unspecified, but the flaw is exploitable remotely through input processed by the affected Java runtime. Successful exploitation gives an attacker arbitrary code execution in the context of the Java process, typically compromising the affected application and potentially the underlying host. Any organization running affected, unpatched Oracle Java SE builds on desktops, servers, or embedded devices is in scope. The flaw is confirmed exploited in the wild (added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03; ransomware use unknown), carries a 25.5% EPSS probability of exploitation within 30 days, and has no known public proof-of-concept.

What to do: Inventory all Oracle Java SE and Java SE Embedded installations and update them to a patched release per Oracle's Critical Patch Update instructions, as CISA's required action directs. Remove or upgrade legacy Java runtimes that no longer receive updates, and uninstall or restrict browser/plugin-based Java where it is not needed. Prioritize internet-facing services and embedded Java deployments given confirmed in-the-wild exploitation.

Affected
Oracle Java SE
Oracle Java SE Embedded
Estimated exposure
masshundreds of millions of installations worldwide (Java SE is one of the most widely deployed software runtimes) — Order of magnitude is based on Java's ubiquity across enterprise desktops, servers, and embedded devices historically; the number of still-unpatched vulnerable instances today is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.

CISA Known Exploited Vulnerability
Affected
Oracle Java SE
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Oracle
Products
Java SE

In the news