CVE-2015-2590
KEVmassRemote Code Execution Vulnerability in Oracle Java SE and Java SE Embedded
CISA: Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
CVE-2015-2590 is an unspecified vulnerability in Oracle's Java Runtime Environment (Java SE, and Java SE Embedded per CISA's naming) that allows a remote attacker to achieve remote code execution. Oracle did not publish technical details, so the exact trigger is unspecified, but the flaw is exploitable remotely through input processed by the affected Java runtime. Successful exploitation gives an attacker arbitrary code execution in the context of the Java process, typically compromising the affected application and potentially the underlying host. Any organization running affected, unpatched Oracle Java SE builds on desktops, servers, or embedded devices is in scope. The flaw is confirmed exploited in the wild (added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03; ransomware use unknown), carries a 25.5% EPSS probability of exploitation within 30 days, and has no known public proof-of-concept.
What to do: Inventory all Oracle Java SE and Java SE Embedded installations and update them to a patched release per Oracle's Critical Patch Update instructions, as CISA's required action directs. Remove or upgrade legacy Java runtimes that no longer receive updates, and uninstall or restrict browser/plugin-based Java where it is not needed. Prioritize internet-facing services and embedded Java deployments given confirmed in-the-wild exploitation.
| Oracle Java SE | — |
| Oracle Java SE Embedded | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
- Affected
- Oracle Java SE
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Oracle
- Products
- Java SE