CVE-2015-0192

critical
Published 2015-07-02 · Modified 2026-05-27
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21883640

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IV70683

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IV70682

OS impact

OSVersionStatusFixed in
redhat rhel5.0affected
redhat rhel6.0affected
redhat rhel7.0affected
suse suse10affected
suse suse11affected
suse suse12affected

Application impact

VendorProductVersionsFixed
ibm ibmjava{"startIncluding":"5.0.0.0","endExcluding":"5.0.16.10"}5.0.16.10

References

CWEs

CWE-269

Verify integrity in audit chain (admin only). AS-IS.