Skip to content
COOEY

EXPOSURES › CVE-2015-2590

CVE-2015-2590

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-2590 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Oracle Java SE contained an unpatched remote code execution vulnerability that was actively exploited in the wild.

An unspecified vulnerability in Oracle Java SE and Java SE Embedded allowed attackers to execute arbitrary code remotely. This failure is critical for DIB organizations because Java is ubiquitous in enterprise environments, and unpatched RCE flaws are a primary vector for ransomware and data breaches. Organizations must rigorously patch Java SE and monitor KEV entries to prevent exploitation.

Shame score — Oracle failed to patch a known, actively exploited RCE vulnerability in a widely deployed product, demonstrating severe negligence and exposing countless systems to compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized