CVE-2015-4902
KEVmassOracle Java SE Deployment Integrity Vulnerability Exploited in the Wild
CISA: Oracle Java SE Integrity Check Vulnerability
CVE-2015-4902 is an unspecified vulnerability in Oracle Java SE, tied to the Java Deployment component, that allows a remote attacker to affect the integrity of affected Java installations; Oracle published limited technical detail and no CVSS score has been assigned. It is triggered through Java's deployment machinery — historically the browser plugin and Java Web Start paths used to launch applets and Web Start content — so exploitation typically requires a user to run attacker-influenced Java content in an unpatched runtime. A successful attacker gains integrity impact (the ability to tamper with data or the deployment process), with the description indicating no confidentiality or availability impact. Anyone running Oracle Java SE builds predating the October 2015 Critical Patch Update is affected, particularly legacy desktop environments that still permit browser applets or Java Web Start. No public proof-of-concept is known, but CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-03-03 based on evidence of active exploitation, and EPSS currently estimates a 13.4% probability of exploitation activity within 30 days (96th percentile).
What to do: Upgrade every Java SE installation to a build from the October 2015 Critical Patch Update or later (Java 8u65+, 7u91+, 6u105+); any currently supported Java release already contains this fix. Inventory endpoints and servers for legacy Java, and disable the Java browser plugin and Java Web Start where they are not needed, since the flaw resides in Java's deployment paths. Because this is CISA KEV-listed, federal agencies must apply vendor updates by the required action deadline — verify installed Java versions via software inventory or endpoint management tooling.
| Oracle Java SE | Prior releases of Java SE 6, 7 and 8, fixed in the October 2015 Critical Patch Update (6u105, 7u91, 8u65); all Java releases from that update onward include the |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.
- Affected
- Oracle Java SE
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Oracle
- Products
- Java SE