First published: Tue Apr 14 2015(Updated: )
Oracle Java SE 7u79 and 8u45 fixes an unspecified vulnerability in the JavaFX component (<a href="https://access.redhat.com/security/cve/CVE-2015-0484">CVE-2015-0484</a>). Upstream has CVSSv2 scored this issue as: 6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P External Reference: <a href="http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html#AppendixJAVA">http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html#AppendixJAVA</a>
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK 6 | =1.7.0-update76 | |
Oracle JDK 6 | =1.8.0-update40 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update76 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update40 | |
Oracle JavaFX | =2.2.76 | |
openSUSE | =13.2 | |
SUSE Linux Enterprise Server | =11-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0484 has a CVSSv2 score of 6.8, indicating a medium severity vulnerability.
To mitigate CVE-2015-0484, upgrade to the latest versions of Oracle Java SE and JavaFX as specified by Oracle.
CVE-2015-0484 affects Oracle JDK 7u76, Oracle JDK 8u40, and specific versions of Oracle JavaFX.
No, CVE-2015-0484 can be exploited without authentication.
CVE-2015-0484 impacts the JavaFX component of Oracle's Java Runtime Environment.