CVE-2015-2638: Critical severity oracle java se 7 vulnerability
Oracle Java SE 6u101, 7u85 and 8u51 fixes an unspecified vulnerability in the 2D component (CVE-2015-2638). Upstream has CVSSv2 scored this issue as: 10.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA
Other sources
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JavaFX 2.2.80; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2638?
CVE-2015-2638 has a CVSSv2 score of 10.0, indicating it is a critical vulnerability.
Which software versions are affected by CVE-2015-2638?
CVE-2015-2638 affects Oracle Java SE versions 6u101, 7u85, and 8u51.
How do I fix CVE-2015-2638?
To fix CVE-2015-2638, update your Oracle Java SE to the latest version available.
Is CVE-2015-2638 a remote code execution vulnerability?
Yes, CVE-2015-2638 can potentially allow remote code execution due to its severity.
What components are impacted by CVE-2015-2638?
CVE-2015-2638 specifically affects the 2D component of Oracle Java.