CVE-2015-4748: High severity oracle java se vulnerability
A flaw was found in the way the Libraries component of OpenJDK verified OCSP (Online Certificate Status Protocol) response. An OCSP response with no nextUpdate date specified was incorrectly handled as having unlimited validity. This could allow a Java application to accept a revoked X.509 certificate as valid if it was presented with an OCSP response generated before certificate revocation.
Other sources
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRoc ...
— Debian
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this Oracle Java SE vulnerability?
The vulnerability ID is CVE-2015-4748.
What is the severity rating of CVE-2015-4748?
The severity rating of CVE-2015-4748 is 7.6 (high).
Which versions of Oracle Java SE are affected by CVE-2015-4748?
Oracle Java SE 6u95, 7u80, and 8u45 are affected by CVE-2015-4748.
How can CVE-2015-4748 affect a system?
CVE-2015-4748 can affect confidentiality, integrity, and availability of a system.
Where can I find more information about CVE-2015-4748?
You can find more information about CVE-2015-4748 on the official Oracle website and the Red Hat website.