First published: Thu Apr 09 2015(Updated: )
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JRockit R28.3.5, allows remote attackers to affect confidentiality via vectors related to JCE.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/IcedTea6 | <1.13.7 | 1.13.7 |
redhat/IcedTea7 | <2.5.5 | 2.5.5 |
BEA JRockit | =r28.3.5 | |
Oracle JDK 6 | =1.5.0-update8 | |
Oracle JDK 6 | =1.6.0-update91 | |
Oracle JDK 6 | =1.7.0-update76 | |
Oracle JDK 6 | =1.8.0-update40 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update81 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update91 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update76 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0478 is classified as a high-severity vulnerability that can affect the confidentiality of data.
To fix CVE-2015-0478, upgrade to the latest versions of affected software, such as IcedTea6 1.13.7 or IcedTea7 2.5.5.
CVE-2015-0478 affects various versions of Oracle Java SE, including versions 5.0u81, 6u91, 7u76, and 8u40, as well as JRockit R28.3.5.
CVE-2015-0478 can be exploited by remote attackers, potentially compromising the confidentiality of the RSA implementation in the affected systems.
No, CVE-2015-0478 is not classified as a zero-day vulnerability as it has been publicly disclosed and patches are available.