EXPOSURES › CVE-2015-2590
CVE-2015-2590
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle Java SE contained an unpatched remote code execution vulnerability that was actively exploited in the wild.
An unspecified vulnerability in Oracle Java SE and Java SE Embedded allowed attackers to execute arbitrary code remotely. This failure is critical for DIB organizations because Java is ubiquitous in enterprise environments, and unpatched RCE flaws are a primary vector for ransomware and data breaches. Organizations must rigorously patch Java SE and monitor KEV entries to prevent exploitation.
Shame score — Oracle failed to patch a known, actively exploited RCE vulnerability in a widely deployed product, demonstrating severe negligence and exposing countless systems to compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |