CVE-2015-2590

Advisory lineage Upstream: 0 Downstream: 28
Analyzed
Published: 16 Jul 2015, 10:00
Last modified:21 Oct 2025, 23:55

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
10 HIGH
v2.0 (nvd)
EPSS Score
66.62% CRITICAL
67% probability +5.08%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Jul 2015, 10:00
Published
Vulnerability first disclosed
03 Mar 2022, 00:00
Added to CISA KEV
Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
24 Mar 2022, 00:00
CISA Remediation Due
Apply updates per vendor instructions.
21 Oct 2025, 23:55
Last Modified
Vulnerability information updated

Description

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 10AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 66.62% Percentile: 99%

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 15.04

  • debiandebian_linux

    7.0 | 8.0

  • opensuseopensuse

    13.1 | 13.2

  • oraclejdk

    1.8.0:update_33 | 1.6.0:update95 | 1.7.0:update75 | 1.7.0:update80 | 1.8.0:update33 | 1.8.0:update45

  • oraclejre

    1.6.0:update_95 | 1.7.0:update_75 | 1.7.0:update_80 | 1.8.0:update_33 | 1.8.0:update_45 | 1.6.0:update95 | 1.7.0:update75 | 1.7.0:update80 | 1.8.0:update33 | 1.8.0:update45

  • redhatenterprise_linux_desktop

    5.0 | 6.0 | 7.0

  • redhatenterprise_linux_eus

    6.6 | 6.7 | 7.1 | 7.2 | 7.3 | 7.4 | 7.5

  • redhatenterprise_linux_for_ibm_z_systems

    6.0_s390x

  • redhatenterprise_linux_for_ibm_z_systems_eus

    6.7_s390x | 7.1_s390x | 7.2_s390x | 7.3_s390x | 7.4_s390x | 7.5_s390x

  • redhatenterprise_linux_for_power_big_endian

    6.0_ppc64 | 7.0_ppc64

  • redhatenterprise_linux_for_power_big_endian_eus

    6.7_ppc64 | 7.1_ppc64 | 7.2_ppc64 | 7.3_ppc64 | 7.4_ppc64 | 7.5_ppc64

  • redhatenterprise_linux_for_power_little_endian

    7.0_ppc64le

  • redhatenterprise_linux_for_power_little_endian_eus

    7.1_ppc64le | 7.2_ppc64le | 7.3_ppc64le | 7.4_ppc64le | 7.5_ppc64le

  • redhatenterprise_linux_server

    5.0 | 6.0 | 7.0

  • redhatenterprise_linux_server_aus

    6.6 | 7.3 | 7.4 | 7.6 | 7.7

  • redhatenterprise_linux_server_tus

    6.6 | 7.3 | 7.6 | 7.7

  • redhatenterprise_linux_workstation

    5.0 | 6.0 | 7.0

  • redhatsatellite

    5.6 | 5.7

  • suselinux_enterprise_debuginfo

    11:sp3 | 11:sp4

  • suselinux_enterprise_desktop

    11:sp3 | 11:sp4 | 12

  • suselinux_enterprise_server

    12

References (26)