CVE-2015-4908: Medium severity oracle javafx vulnerability
Oracle Java SE 8u65 fixes an unspecified vulnerability in the JavaFX component (CVE-2015-4908). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA
Other sources
Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2015-4906 and CVE-2015-4916.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4908?
CVE-2015-4908 has a CVSSv2 score of 5.0, indicating a medium severity vulnerability.
How do I fix CVE-2015-4908?
To fix CVE-2015-4908, update your Java and JavaFX to the recommended versions 1.8.0-oracle-1:1.8.0.65-1jpp.3.el6_7 or 1.8.0-oracle-1:1.8.0.65-1jpp.3.el7_1.
What software is affected by CVE-2015-4908?
CVE-2015-4908 affects Oracle Java SE, specifically versions of JavaFX and JDK 1.8.0 update 60.
Is CVE-2015-4908 related to Java Runtime Environment?
Yes, CVE-2015-4908 impacts the Oracle Java Runtime Environment (JRE) in the affected versions.
Can CVE-2015-4908 be exploited remotely?
CVE-2015-4908 can be exploited remotely due to its nature as a vulnerability in the JavaFX component.