First published: Tue Oct 20 2015(Updated: )
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serialization.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK 6 | =1.6.0-update101 | |
Oracle JDK 6 | =1.7.0-update85 | |
Oracle JDK 6 | =1.8.0-update51 | |
Oracle JDK 6 | =1.8.0-update60 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update_101 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update_85 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update_51 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update_60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4805 has a high severity level due to its potential impact on confidentiality, integrity, and availability.
To fix CVE-2015-4805, update Oracle Java SE to a version that is not affected by this vulnerability.
CVE-2015-4805 affects Oracle Java SE 6u101, 7u85, and 8u60, as well as Java SE Embedded 8u51.
Remote attackers can exploit CVE-2015-4805 to compromise systems running the affected versions of Oracle Java.
CVE-2015-4805 involves a vulnerability in the Serialization component, specifically related to the ObjectStreamClass in Oracle Java.