CVE-2015-2590: Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
An unspecified flaw was found in the Libraries component in OpenJDK. ObjectInputStream's readSerialData() could, in certain cases, incorrectly perform deserialization of data from serialized input. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
Other sources
An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
— CISA
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and ...
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/openjdk-8to a version that resolves this vulnerability.Fixed in 8u442-ga-2
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2590?
The severity of CVE-2015-2590 is critical with a severity value of 10.
Which software versions are affected by CVE-2015-2590?
Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 are affected by CVE-2015-2590.
How can remote attackers exploit CVE-2015-2590?
Remote attackers can exploit CVE-2015-2590 to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
Where can I find more information about CVE-2015-2590?
You can find more information about CVE-2015-2590 on the Oracle website and the Trend Micro blog.
What is the remedy for CVE-2015-2590?
Apply the patches provided by Oracle and ensure that you are using the latest version of Oracle Java SE or Java SE Embedded.