CVE-2015-2664: Medium severity oracle java se 7 vulnerability
Oracle Java SE 6u101, 7u85 and 8u51 fixes an unspecified vulnerability in the Deployment component (CVE-2015-2664). Upstream has CVSSv2 scored this issue as: 6.9/AV:L/AC:M/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA
Other sources
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2664?
CVE-2015-2664 has a CVSSv2 score of 6.9, indicating a medium severity risk.
How do I fix CVE-2015-2664?
To fix CVE-2015-2664, update to the latest version of Oracle Java SE or apply the appropriate patches as released by Oracle.
Which Oracle products are affected by CVE-2015-2664?
CVE-2015-2664 affects Oracle JDK and JRE versions 1.6.0 update 95, 1.7.0 update 80, and 1.8.0 update 45.
What type of vulnerability is CVE-2015-2664?
CVE-2015-2664 is an unspecified vulnerability in the Deployment component of Oracle Java.
Can CVE-2015-2664 be exploited remotely?
Yes, CVE-2015-2664 can potentially be exploited remotely due to its nature in the Deployment component.