First published: Tue Oct 20 2015(Updated: )
Oracle Java SE 8u65 fixes an unspecified vulnerability in the JavaFX component (<a href="https://access.redhat.com/security/cve/CVE-2015-4908">CVE-2015-4908</a>). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N External Reference: <a href="http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA">http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA</a>
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.8.0-oracle-1:1.8.0.65-1jpp.3.el6_7 | 1.8.0-oracle-1:1.8.0.65-1jpp.3.el6_7 |
redhat/java | <1.8.0-oracle-1:1.8.0.65-1jpp.3.el7_1 | 1.8.0-oracle-1:1.8.0.65-1jpp.3.el7_1 |
Oracle JavaFX | =2.2.85 | |
Oracle JDK 6 | =1.8.0-update60 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update_60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4908 has a CVSSv2 score of 5.0, indicating a medium severity vulnerability.
To fix CVE-2015-4908, update your Java and JavaFX to the recommended versions 1.8.0-oracle-1:1.8.0.65-1jpp.3.el6_7 or 1.8.0-oracle-1:1.8.0.65-1jpp.3.el7_1.
CVE-2015-4908 affects Oracle Java SE, specifically versions of JavaFX and JDK 1.8.0 update 60.
Yes, CVE-2015-4908 impacts the Oracle Java Runtime Environment (JRE) in the affected versions.
CVE-2015-4908 can be exploited remotely due to its nature as a vulnerability in the JavaFX component.