CVE-2015-2590: Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-03. EPSS: 25.5% chance of exploitation in the next 30 days.

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Oracle JDK: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only
  • Oracle JRE: version 1.6.0 only; version 1.7.0 only; version 1.8.0 only
  • Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Eus: version 6.6 only; version 6.7 only; version 7.1 only; version 7.2 only; version 7.3 only; version 7.4 only; …
  • Red Hat Enterprise Linux For IBM Z Systems: version 6.0_s390x only
  • Red Hat Enterprise Linux For IBM Z Systems Eus: version 6.7_s390x only; version 7.1_s390x only; version 7.2_s390x only; version 7.3_s390x only; version 7.4_s390x only; version 7.5_s390x only
  • Red Hat Enterprise Linux For Power Big Endian: version 6.0_ppc64 only; version 7.0_ppc64 only
  • Red Hat Enterprise Linux For Power Big Endian Eus: version 6.7_ppc64 only; version 7.1_ppc64 only; version 7.2_ppc64 only; version 7.3_ppc64 only; version 7.4_ppc64 only; version 7.5_ppc64 only
  • Red Hat Enterprise Linux For Power Little Endian: version 7.0_ppc64le only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 7.1_ppc64le only; version 7.2_ppc64le only; version 7.3_ppc64le only; version 7.4_ppc64le only; version 7.5_ppc64le only
  • Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.6 only; version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Server Tus: version 6.6 only; version 7.3 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Satellite: version 5.6 only; version 5.7 only
  • Suse Linux Enterprise Debuginfo: version 11 only
  • Suse Linux Enterprise Desktop: version 11 only; version 12 only
  • Suse Linux Enterprise Server: version 12 only

Published 2015-07-16. Last modified 2026-06-17.