CVE-2015-0478: Medium severity oracle java se vulnerability
It was found that the RSA implementation in Java Cryptography Extension (JCE) component in OpenJDK did not follow recommended practices for implementing RSA signatures.
Acknowledgement:
This issue was discovered by Florian Weimer of Red Hat Product Security.
Other sources
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect confidentiality via vectors related to JCE.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0478?
CVE-2015-0478 is classified as a high-severity vulnerability that can affect the confidentiality of data.
How do I fix CVE-2015-0478?
To fix CVE-2015-0478, upgrade to the latest versions of affected software, such as IcedTea6 1.13.7 or IcedTea7 2.5.5.
Which software is affected by CVE-2015-0478?
CVE-2015-0478 affects various versions of Oracle Java SE, including versions 5.0u81, 6u91, 7u76, and 8u40, as well as JRockit R28.3.5.
What type of attack can exploit CVE-2015-0478?
CVE-2015-0478 can be exploited by remote attackers, potentially compromising the confidentiality of the RSA implementation in the affected systems.
Is CVE-2015-0478 a zero-day vulnerability?
No, CVE-2015-0478 is not classified as a zero-day vulnerability as it has been publicly disclosed and patches are available.