Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-4748

Опубликовано: 14 июл. 2015
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.

A flaw was found in the way the Libraries component of OpenJDK verified Online Certificate Status Protocol (OCSP) responses. An OCSP response with no nextUpdate date specified was incorrectly handled as having unlimited validity, possibly causing a revoked X.509 certificate to be interpreted as valid.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-299
https://bugzilla.redhat.com/show_bug.cgi?id=1242281OpenJDK: incorrect OCSP nextUpdate checking (Libraries, 8075374)

EPSS

Процентиль: 94%
0.1225
Средний

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.

nvd
около 10 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.

debian
около 10 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRoc ...

github
около 3 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.

oracle-oval
около 10 лет назад

ELSA-2015-1526: java-1.6.0-openjdk security update (IMPORTANT)

EPSS

Процентиль: 94%
0.1225
Средний

4.3 Medium

CVSS2