Cyber Resilience

CVE-2015-2590

Redhat Enterprise Linux Eus 6.6 … 7.5

CISA KEVActive ExploitationEUVD Exploited
Published
16 July 2015
Modified
21 April 2026
KEV Added
03 March 2022
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.25 98th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2015-2590 is a critical-severity an unspecified weakness vulnerability in Redhat Enterprise Linux Eus. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 2% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2015-2590 is an unspecified vulnerability affecting the Libraries component of Oracle Java SE versions 6u95, 7u80, and 8u45, as well as Java SE Embedded versions 7u75 and 8u33. It is distinct from CVE-2015-4732 and carries a CVSS 3.1 base score of 9.8, reflecting network-accessible attack vectors with no required privileges or user interaction.

Remote attackers can exploit the flaw via unknown vectors to impact confidentiality, integrity, and availability on affected systems. The vulnerability allows complete compromise of the targeted Java runtime environment without authentication.

Advisories from OpenSUSE and Red Hat, including RHSA-2015-1228, address the issue through updated Java packages that remediate the Libraries component exposure in supported distributions. No further details on exploitation in the wild or additional mitigations beyond vendor patches are provided in the references.

EU & UK References

Vulnerability Data

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.

CWE(s)
KEV Date Added
03 March 2022

Related Threats

CVEs Like This One

CVE-2015-4902Same product: Opensuse Opensuseboth on KEV
CVE-2016-3718Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2016-3715Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2015-4495Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2013-1690Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2016-3427Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2013-1675Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2016-1646Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2014-3153Same product: Canonical Ubuntu Linuxboth on KEV
CVE-2019-11043Same product: Canonical Ubuntu Linuxboth on KEV

Affected Assets

oracle
jdk
1.6.0, 1.7.0, 1.8.0
oracle
jre
1.6.0, 1.7.0, 1.8.0
canonical
ubuntu linux
12.04, 14.04, 15.04
debian
debian linux
7.0, 8.0
suse
linux enterprise debuginfo
11
opensuse
opensuse
13.1, 13.2
suse
linux enterprise desktop
11, 12
suse
linux enterprise server
12
redhat
satellite
5.6, 5.7
redhat
enterprise linux desktop
5.0, 6.0, 7.0
+11 more product configuration(s) — see NVD for full list

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References