CVE-2015-4906: Medium severity oracle javafx vulnerability
Oracle Java SE 8u65 fixes an unspecified vulnerability in the JavaFX component (CVE-2015-4906). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA
Other sources
Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors related to JavaFX, a different vulnerability than CVE-2015-4908 and CVE-2015-4916.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4906?
CVE-2015-4906 has a CVSSv2 score of 5.0, indicating a moderate severity vulnerability.
How do I fix CVE-2015-4906?
To fix CVE-2015-4906, upgrade to Oracle Java SE 8u65 or later.
Which software versions are affected by CVE-2015-4906?
CVE-2015-4906 affects Oracle Java 1.8.0 update 60 and earlier versions.
What component is impacted by CVE-2015-4906?
CVE-2015-4906 impacts the JavaFX component of Oracle Java SE.
Is authentication required to exploit CVE-2015-4906?
No, CVE-2015-4906 can be exploited without authentication.