Skip to content
COOEY

EXPOSURES › CVE-2015-4902

CVE-2015-4902

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-4902 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatched

Oracle Java SE suffered an integrity vulnerability that was actively exploited in the wild, highlighting the severe risks of unpatched legacy software.

An unspecified integrity vulnerability in Oracle Java SE allowed remote attackers to affect system integrity through unknown deployment vectors. This failure is critical for DIB organizations because unpatched Java environments are a common entry point for ransomware and data breaches, directly impacting CMMC/NIST 800-171 compliance by failing to mitigate known, actively exploited threats. Organizations must rigorously patch all Java SE instances and monitor KEV catalogs to prevent similar exposures.

Shame score — The vulnerability was actively exploited in the wild (KEV), indicating a failure to patch a known, high-severity flaw that attackers were already leveraging against systems.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related to deployment.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized