← Vulnerability feed

Vulnerability record · CVE-2015-4902 · published 22 October 2015

CVE-2015-4902: Oracle Java SE Deployment integrity check bypass

Oracle · Jdk

CVE-2015-4902 is an unspecified vulnerability in the Deployment component of Oracle Java SE 6u101, 7u85, and 8u60. It allows remote attackers to affect integrity via unknown vectors, and the record provides no further technical detail on the root cause. Because Java Deployment handles applet and Web Start execution, a bypass here can undermine the security checks that gate untrusted code.

5.3 CVSS 3.1 Medium CISA KEV since 3 Mar 2022 EPSS 14% · top 3.7% CWE-284 · Improper access control
5.3CVSS 3.1 base score, v2 5.0
14%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
21Affected product versions listed by NVD
45References
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is in CISA KEV with known exploitation and a high EPSS percentile, but the CVSS impact is limited to integrity (5.3) and the technical details are unspecified.

What it is

CVE-2015-4902 is an unspecified vulnerability in the Deployment component of Oracle Java SE 6u101, 7u85, and 8u60. It allows remote attackers to affect integrity via unknown vectors, and the record provides no further technical detail on the root cause. Because Java Deployment handles applet and Web Start execution, a bypass here can undermine the security checks that gate untrusted code.

Impact

An attacker can affect the integrity of the affected Java SE installation, potentially bypassing Deployment security checks. The record does not specify what data or code can be altered, so the exact attacker gain is unknown.

Attack surface

The CVSS vector is network-reachable with no privileges and no user interaction required (AV:N/AC:L/PR:N/UI:N), so it is exploitable remotely over the network. The description says the flaw is in Deployment, but does not state the exact entry point.

Exploitation

CVE-2015-4902 is listed in CISA KEV with a due date of 2022-03-24, indicating known exploitation in the wild. EPSS gives a 30-day probability of 0.13354 (96.2nd percentile), and no ransomware campaign use is documented.

What to do

  • Apply the Oracle October 2015 CPU update or later for Java SE 6u101, 7u85, and 8u60, per the vendor advisory.
  • Apply the referenced Red Hat, SUSE/openSUSE, and Gentoo errata for bundled JDK/JRE packages.
  • Remove or disable the Java browser plugin and Web Start where they are not required.
  • Restrict outbound network access from systems running Java SE to reduce remote reachability.
  • Track Java SE versions in inventory and prioritize hosts still running 6u101, 7u85, or 8u60.

Detection

  • Inventory endpoints and servers for Java SE versions 6u101, 7u85, and 8u60.
  • Monitor for Java Deployment or Web Start processes making unexpected outbound network connections.
  • Alert on execution of untrusted JAR or JNLP content from external or user-writable locations.
  • Review proxy and DNS logs for Java processes contacting untrusted hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2015-4902 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Oracle Java SE Integrity Check Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

21 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00009.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1926.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1927.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1928.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2506.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2507.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2508.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2509.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2518.html Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html PatchVendor Advisory
http://www.securityfocus.com/bid/77241 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1033884 Broken LinkThird Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2016:1430 Third Party Advisory
https://security.gentoo.org/glsa/201603-11 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00009.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00000.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00001.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00003.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00004.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00006.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00014.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00005.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1926.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1927.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1928.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2506.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2507.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2508.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2509.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2518.html Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html PatchVendor Advisory

Track CVE-2015-4902 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed9.8CVE-2020-12641Roundcube Webmail OS command injection via image conversion path settingsRoundcube Webmail before 1.4.4 passes the im_convert_path and im_identify_path configuration settings to a shell without sanitization in rcube_image.…KEVEPSS 84%analysed9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2015-4902), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.