CVE-2015-4731: Critical severity oracle java se 7 vulnerability
It was discovered that the JMX component in OpenJDK failed to properly handle MBean connection proxy classes. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
Other sources
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; Java SE Embedded 7u75; and Java SE Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2015-4731.
What software is affected by this vulnerability?
Oracle Java SE 6u95, 7u80, and 8u45; Java SE Embedded 7u75; and Java SE Embedded 8u33 are affected by this vulnerability.
What is the severity of CVE-2015-4731?
The severity of CVE-2015-4731 is critical.
How does this vulnerability impact confidentiality, integrity, and availability?
This vulnerability allows remote attackers to affect confidentiality, integrity, and availability.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following references: [Reference 1](http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA), [Reference 2](https://rhn.redhat.com/errata/RHSA-2015-1230.html), [Reference 3](https://rhn.redhat.com/errata/RHSA-2015-1229.html).