CVE-2015-4732: Critical severity oracle java se 7 vulnerability
It was discovered that the Libraries component of OpenJDK failed to check current context / thread while performing object deserialization, possibly leading to incorrect input deserialization. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
Other sources
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-2590.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2015-4732.
What is the severity of CVE-2015-4732?
The severity of CVE-2015-4732 is critical.
Which software versions are affected by CVE-2015-4732?
Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 are affected.
How does CVE-2015-4732 impact confidentiality, integrity, and availability?
CVE-2015-4732 can affect confidentiality, integrity, and availability, but the specific impact is unknown.
Are there any remedies available for CVE-2015-4732?
Remedies are available for Ubuntu openjdk-6, openjdk-7, and openjdk-8, as well as Oracle JDK and JRE versions 1.6.0-update95, 1.7.0-update75, 1.7.0-update80, 1.8.0-update_33, and 1.8.0-update_45.