JDK: unspecified Java sandbox restrictions bypass
Published Jul 2, 2015
9.8
CRITICALCVSS 3.1
EPSS 3.98%
Description
Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.
Affected products
No data.
Configuration 1
Configuration 2
- 5.0
- 6.0
- 7.0
- 5.0
- 6.0
- 7.0
- 6.6
- 6.6
- 7.1
- 7.2
- 7.3
- 7.4
- 7.5
- 5.0
- 6.0
- 7.0
Configuration 3
- 10
- 11
- 11
- 12
- 12
No data.
Red Hat Enterprise Linux 5 Supplementary
java-1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el5
Fixed · RHSA-2015:1021
Red Hat Enterprise Linux 5 Supplementary
java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5
Fixed · RHSA-2015:1006
Red Hat Enterprise Linux 5 Supplementary
java-1.7.0-ibm-1:1.7.0.9.0-1jpp.1.el5
Fixed · RHSA-2015:1007
Red Hat Satellite 5.6
java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5
Fixed · RHSA-2015:1091
Red Hat Satellite 5.7
java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6
Fixed · RHSA-2015:1091
Supplementary for Red Hat Enterprise Linux 6
java-1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el6_6
Fixed · RHSA-2015:1021
Supplementary for Red Hat Enterprise Linux 6
java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6
Fixed · RHSA-2015:1006
Supplementary for Red Hat Enterprise Linux 6
java-1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el6_6
Fixed · RHSA-2015:1020
Supplementary for Red Hat Enterprise Linux 7
java-1.7.1-ibm-1:1.7.1.3.0-1jpp.2.ael7b_1
Fixed · RHSA-2015:1020
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 Supplementary | java-1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el5 | Fixed | RHSA-2015:1021 |
| Red Hat Enterprise Linux 5 Supplementary | java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5 | Fixed | RHSA-2015:1006 |
| Red Hat Enterprise Linux 5 Supplementary | java-1.7.0-ibm-1:1.7.0.9.0-1jpp.1.el5 | Fixed | RHSA-2015:1007 |
| Red Hat Satellite 5.6 | java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5 | Fixed | RHSA-2015:1091 |
| Red Hat Satellite 5.7 | java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6 | Fixed | RHSA-2015:1091 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el6_6 | Fixed | RHSA-2015:1021 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6 | Fixed | RHSA-2015:1006 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el6_6 | Fixed | RHSA-2015:1020 |
| Supplementary for Red Hat Enterprise Linux 7 | java-1.7.1-ibm-1:1.7.1.3.0-1jpp.2.ael7b_1 | Fixed | RHSA-2015:1020 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed May 27, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.98% (0.03982) | 90.17th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.54% (0.04542) | 90.31th | v5 (v2026.06.15) |
| Mar 17, 2025 | 2.50% (0.02501) | 84.27th | v4 (v2025.03.14) |
| Dec 12, 2024 | 3.55% (0.03550) | 91.95th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.55% (0.03550) | 90.14th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.78% (0.03779) | 85.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.78% (0.03779) | 84.01th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.78% (0.03779) | 67.21th | v2 (v2022.01.01) |
References (17)
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00013.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00014.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00015.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00022.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00031.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1006.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1007.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1020.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1021.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1091.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV70682 vendor-advisoryx_refsource_AIXAPARVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV70683 vendor-advisoryx_refsource_AIXAPARVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21883640 x_refsource_CONFIRMVendor Advisory
- https://access.redhat.com/security/cve/CVE-2015-0192 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1219212 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2015-0192
- https://www.cve.org/CVERecord?id=CVE-2015-0192
Change history (0)
No recorded changes yet.