CVE-2015-4842: Medium severity oracle java se 7 vulnerability
An information disclosure flaw was found in the JAXP component of OpenJDK. An untrusted Java application or applet could use this flaw to get information about user home directory location (the content of the "user.dir" system property), hence bypassing certain Java sandbox restrictions.
Other sources
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality via vectors related to JAXP.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4842?
CVE-2015-4842 is classified as a medium severity vulnerability due to its potential to lead to information disclosure.
How do I fix CVE-2015-4842?
To mitigate CVE-2015-4842, users should update to the latest versions of Oracle Java SE that address this vulnerability.
What versions are affected by CVE-2015-4842?
CVE-2015-4842 affects Oracle Java SE 6u101, 7u85, 8u60, and Java SE Embedded 8u51.
What type of vulnerability is CVE-2015-4842?
CVE-2015-4842 is an information disclosure vulnerability found in the JAXP component of OpenJDK.
Who can be affected by CVE-2015-4842?
Remote attackers can exploit CVE-2015-4842 to gain unauthorized access to sensitive information.