Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2625

Опубликовано: 02 нояб. 2014
Источник: redhat
CVSS2: 2.6

Описание

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JSSE.

A flaw was found in the way the JSSE component in OpenJDK performed X.509 certificate identity verification when establishing a TLS/SSL connection to a host identified by an IP address. In certain cases, the certificate was accepted as valid if it was issued for a host name to which the IP address resolves rather than for the IP address.

Дополнительная информация

Статус:

Low
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1241965OpenJDK: name for reverse DNS lookup used in certificate identity check (JSSE, 8067694)

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JSSE.

nvd
около 10 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JSSE.

debian
около 10 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRoc ...

github
около 3 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JSSE.

fstec
около 10 лет назад

Уязвимость программных платформ Java Platform и Jrockit, позволяющая нарушителю нарушить конфиденциальность информации

2.6 Low

CVSS2