Evidence dossier

CVE-2015-4902

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

Exploited in the wild (CISA KEV since Mar 3, 2022). NVD reports CVSS 2.0 5.0. EPSS estimates 13.4% exploit likelihood as of Aug 27, 2026.

69.169.5Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

State
PUBLISHED
Published
Oct 21, 2015
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    oracle

    Record text: Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

    Inspect raw assertion
    Field
    container
    Value
    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Oracle Java SE Integrity Check Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Oracle Java SE Integrity Check Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 13.35% probability · 96.12th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.133540000000; percentile 0.961230000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Mar 3, 2022 · first observed Jul 19, 2026

Exploit likelihood13.35%

FIRST EPSS · score date Aug 27, 2026 · 96.1th percentile · first observed Aug 27, 2026

SeverityCVSS 5.0

NVD · CVSS 2.0 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
oracleOriginal assertion
Record text

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

Inspect raw assertion
Field
container
Value
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Oracle Java SE Integrity Check Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Oracle Java SE Integrity Check Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

13.35% probability · 96.12th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.133540000000; percentile 0.961230000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
64Underlying assertions
21Canonical products
64Target assertions
0Constraint assertions

Grouped from 3 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

22 scope groups

oracle · source assertedn/an/aDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · OPERATING SYSTEMopensuseleapVulnerable target · 1 assertions
Version 42.1Canonical identity product-c27aedc6088fe47e75f3a72d532ce7dcfb4a151fd6deaeecc763cf1d10026925Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4863be36-d16a-4d75-90d9-fd76db5b48b7
NVD CPE · OPERATING SYSTEMopensuseopensuseVulnerable target · 1 assertions
Version 13.2Canonical identity product-66ca8198d1887ac9754d1aad85d76f1edfc54c873eb2cd9bedf566863f5e07bdLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    03117df1-3bec-4b8d-ad63-dbbdb2126081
NVD CPE · APPLICATIONoraclejdkVulnerable target · 3 assertions
Version 1.6.0; Version 1.7.0; Version 1.8.0Canonical identity product-6c94a14e5689a64227066e3f60eeb2b8b30045bcbf08047234f29f3fdd35d120Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:jdk:1.7.0:update85:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8d5a88f0-6f37-402f-8153-92b4d4083313
  2. cpe:2.3:a:oracle:jdk:1.6.0:update101:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3cb2a0a4-f70c-4161-9504-781e49925180
  3. cpe:2.3:a:oracle:jdk:1.8.0:update60:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5ab1b679-623a-4ade-b235-a35efca0cc9f
NVD CPE · APPLICATIONoraclejreVulnerable target · 3 assertions
Version 1.6.0; Version 1.7.0; Version 1.8.0Canonical identity product-70c0761d49c3bbe44615490ef7b613557bcd3ccdfa71d09d74202c114d277fb7Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:jre:1.7.0:update85:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2a9570f9-cb9a-4e85-bad4-7cf36e6d45a9
  2. cpe:2.3:a:oracle:jre:1.8.0:update60:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    615d100b-efb3-49b1-9cbc-5aee8259cd9a
  3. cpe:2.3:a:oracle:jre:1.6.0:update101:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4d32c4c3-f0b1-4fe0-b36d-c959f8a19a83
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_desktopVulnerable target · 3 assertions
Version 5.0; Version 6.0; Version 7.0Canonical identity product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5aeLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ee249e1b-a1fd-4e08-aa71-a0e1f10ffe97
  2. cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    33c068a4-3780-4eab-a937-6082df847564
  3. cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    133aafa7-af42-4d7b-8822-aa2e85611bf5
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_eusVulnerable target · 5 assertions
Version 6.7; Version 7.2; Version 7.3; Version 7.4; Version 7.5Canonical identity product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_eus:7.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ae1d81a1-cd24-4b17-8afd-dc95e90ad7d0
  2. cpe:2.3:o:redhat:enterprise_linux_eus:7.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    807c024a-f8e8-4b48-a349-4c68cd252ca1
  3. cpe:2.3:o:redhat:enterprise_linux_eus:7.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f96e3779-f56a-45ff-bb3d-4980527d721e
  4. cpe:2.3:o:redhat:enterprise_linux_eus:6.7:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    967ec28a-607f-48f4-ad64-5e3041c768f0
  5. cpe:2.3:o:redhat:enterprise_linux_eus:7.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0cf73560-2f5b-4723-a8a1-9aadbb3ada00
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_eus_compute_nodeVulnerable target · 2 assertions
Version 7.2; Version 7.3Canonical identity product-9ff3bc0adcc5343851d69d4a833815e08f0c8d24134495b38f50fdf38d2f17b2Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_eus_compute_node:7.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f3bf4697-f1f9-446a-ab1e-7eb7ddebc036
  2. cpe:2.3:o:redhat:enterprise_linux_eus_compute_node:7.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d38a5df8-5b7f-45ef-8cd3-119e1ce96751
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_ibm_z_systemsVulnerable target · 3 assertions
Version 5.0_s390x; Version 6.0_s390x; Version 7.0_s390xCanonical identity product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:6.0_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c84eaae7-0249-4ea1-b8d3-e039b03acdc3
  2. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:5.0_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    90be67da-1f52-43dd-8610-8f8d414c0189
  3. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2148300c-ecbd-4ed5-a164-79629859dd43
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_ibm_z_systems_eusVulnerable target · 5 assertions
Version 6.7_s390x; Version 7.2_s390x; Version 7.3_s390x; Version 7.4_s390x; Version 7.5_s390xCanonical identity product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fdLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:7.5_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0f8eb695-5ea3-46d2-941e-d7f01ab99a48
  2. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:7.2_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    357fde3e-2248-4bcd-b726-97c4d92fdcb7
  3. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:7.3_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e420b889-bb89-4b64-b0e0-7e9b8545b959
  4. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:7.4_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b908aef5-67ce-42d4-961d-c0e7adb78add
  5. cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:6.7_s390x:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    837f0d24-99b3-4093-a45a-53adb0367fcf
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_power_big_endianVulnerable target · 3 assertions
Version 5.0_ppc; Version 6.0_ppc64; Version 7.0_ppc64Canonical identity product-fd0893ef7253031c8ee72effb6fcc65181f9b3f5e01f8f48b6a6ab89a31380a9Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:5.0_ppc:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    29bbf1ac-f31f-4251-8054-0d89a8e6e990
  2. cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0_ppc64:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8bcf87fd-9358-42a5-9917-25df0180a5a6
  3. cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:6.0_ppc64:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6d8d654f-2442-4ea0-af89-6ac2cd214772
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_power_big_endian_eusVulnerable target · 5 assertions
Version 6.7_ppc64; Version 7.2_ppc64; Version 7.3_ppc64; Version 7.4_ppc64; Version 7.5_ppc64Canonical identity product-c09e1a6c06a60f75d4f5a3a91108bcb8e8b7418b4d0bcbe56608e9eba3cd934bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.5_ppc64:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4319b943-7b19-468d-a160-5895f7f997a3
  2. cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.2_ppc64:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8e5b5f9e-d749-45e5-8538-7ced9620c00c
  3. cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.4_ppc64:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9b8b2e32-b838-4e51-baa2-764089d2a684
  4. cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.3_ppc64:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    188019bf-3700-4b3f-bfa5-553b2b545b7f
  5. cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:6.7_ppc64:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9835090f-120a-4a53-b4a8-375dd6999167
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_power_little_endianVulnerable target · 1 assertions
Version 7.0_ppc64leCanonical identity product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:7.0_ppc64le:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7a584aaa-a14f-4c64-8fed-675dc36f69a3
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_power_little_endian_eusVulnerable target · 4 assertions
Version 7.2_ppc64le; Version 7.3_ppc64le; Version 7.4_ppc64le; Version 7.5_ppc64leCanonical identity product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:7.5_ppc64le:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3a2e3637-b6a6-4da9-8b0a-e91f22130a45
  2. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:7.4_ppc64le:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e9a24d0c-604d-4421-afa6-5d541da2e94d
  3. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:7.3_ppc64le:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cfe6c909-798b-4b7a-9bd4-6741933dbc1f
  4. cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:7.2_ppc64le:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d373a806-8a25-4bd4-8511-879d8755c326
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_for_scientific_computingVulnerable target · 2 assertions
Version 6.0; Version 7.0Canonical identity product-d22fc88b6b85afc426c8220428110aecfb39a59d3b7ddf5757cf39cb9f5feb2fLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    634c23ac-ac9c-43f4-bed8-1c720816d5e3
  2. cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    37ce1dc7-72c5-483c-8921-0b462c8284d1
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_serverVulnerable target · 3 assertions
Version 5.0; Version 6.0; Version 7.0Canonical identity product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9deaLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9bbcd86a-e6c7-4444-9d74-f861084090f0
  2. cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    51ef4996-72f4-4fa4-814f-f5991e7a8318
  3. cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    54d669d4-6d7e-449d-80c1-28fa44f06ffe
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_server_from_rhuiVulnerable target · 3 assertions
Version 5.0; Version 6.0; Version 7.0Canonical identity product-97a1380f0ac22d5543df434518bceb2f4b47c884bd4e990396f64e72afa98accLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_server_from_rhui:6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0ae981d4-0ca1-46fa-8e91-e1a4d5b31383
  2. cpe:2.3:o:redhat:enterprise_linux_server_from_rhui:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f732c7c9-a9cc-4def-a8be-d0f18c944c78
  3. cpe:2.3:o:redhat:enterprise_linux_server_from_rhui:5.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8821e5fe-319d-40ab-a515-d56c1893e6f8
NVD CPE · OPERATING SYSTEMredhatenterprise_linux_workstationVulnerable target · 3 assertions
Version 5.0; Version 6.0; Version 7.0Canonical identity product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d0ac5cd5-6e58-433c-9eb3-6dfe5656463e
  2. cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e5ed5807-55b7-47c5-97a6-03233f4fbc3a
  3. cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    825ece2d-e232-46e0-a047-074b34db1e97
NVD CPE · APPLICATIONredhatsatelliteVulnerable target · 2 assertions
Version 5.6; Version 5.7Canonical identity product-8270111f4cc417bcdc58b8fcee5af06573840731d43a3d04b238435408400874Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:redhat:satellite:5.7:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    85ea16e0-9261-45c4-840f-5366e9eac5e1
  2. cpe:2.3:a:redhat:satellite:5.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d4840254-cc76-4113-bc61-360bd15582b9
NVD CPE · APPLICATIONsuselinux_enterprise_module_for_legacyVulnerable target · 1 assertions
Version 12Canonical identity product-2ed4d80ed12721f6ebc20d0939cfdb7f085ade620bbe2f57d6dcaea9c2741a25Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:suse:linux_enterprise_module_for_legacy:12:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c0257d57-abf4-49ff-aa59-1b82faa6d147
NVD CPE · OPERATING SYSTEMsuselinux_enterprise_serverVulnerable target · 7 assertions
Version 10; Version 11; Version 12Canonical identity product-4f2240e45c4385f8980643ce838561b90551012dc317022ee66a7d71a9db8e28Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:ltss:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cb6476c7-03f2-4939-ab85-69aa524516d9
  2. cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2470c6e8-2024-4cf5-9982-cff50e88eae9
  3. cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:ltss:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    35bbd83d-bdc7-4678-be94-639f59281139
  4. cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    55c5561f-be86-4eea-99d4-8697f8bd9dfe
  5. cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e534c201-bcc5-473c-aaa7-aab97ceb5437
  6. cpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    15fc9014-bd85-4382-9d04-c0703e901d7a
  7. cpe:2.3:o:suse:linux_enterprise_server:12:sp1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2076747f-a98e-4dd9-9b52-bf1732bcad3d
NVD CPE · OPERATING SYSTEMsuselinux_enterprise_software_development_kitVulnerable target · 4 assertions
Version 11; Version 12Canonical identity product-bd4950335ff1f3f03b9dd6fa5c596f7c67c9ea6d150272de074ec3767af3532aLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:sp1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5a633996-2fd7-467c-baa6-529e16bd06d1
  2. cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1831d45a-ee6e-4220-8f8c-248b69520948
  3. cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2f7f8866-dead-44d1-ab10-21ee611aa026
  4. cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d41a798e-0d69-43c7-9a63-1e5921138eac

Affected-product evidence

Accepted scope and product mapping

21 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
623dd85b-21d2-4a24-9542-ed3606bb2143719ac3f5-f23a-4b97-bccf-b48aa4632b20a9b723c5-3085-4be0-a701-7b881b4fe5bbedb3ebea-3a92-4101-958e-3dd5e729d757
Mapping establishedEvidence supported

vendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-2ed4d80ed12721f6ebc20d0939cfdb7f085ade620bbe2f57d6dcaea9c2741a25

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
70d7845d-f511-4238-9772-11472acac15b
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fd

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2c7fe1d0-5564-4b4d-a857-1123899c9b3669331ec1-8bdb-4589-ad8f-e0851053be9aa8b76f08-9ee9-4411-b067-ae04338deac7d4eda358-74b2-4e46-828c-9253b966656cf3654ffc-b98b-4d93-9378-cdef900d26d3
Mapping establishedEvidence supported

vendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-4f2240e45c4385f8980643ce838561b90551012dc317022ee66a7d71a9db8e28

Source class
Nvd cpe vulnerable target
Assertions
7
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2fec7afc-d0ff-4781-828f-ee090f076eac44da1a6d-dda3-4b00-bae9-e481bbc3b2a55116a8c3-8d58-4349-8fdb-f6e446d0598b5eb94cf3-6ae3-4d5d-a27a-485fcaf0f1bb6c756364-7256-4650-86c2-41d1fa245c7f84ac3891-225e-4129-9db0-b8997d3421459aad2a3b-af76-4361-814a-2b2bed229d36
Mapping establishedEvidence supported

vendor-f98e1750e4b030e2bb71130d14421ff255427227a8b696c92978cf6c77fc265d · product-66ca8198d1887ac9754d1aad85d76f1edfc54c873eb2cd9bedf566863f5e07bd

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f534ff3d-f21a-45ff-9a56-4b95ada1a7df
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-6c94a14e5689a64227066e3f60eeb2b8b30045bcbf08047234f29f3fdd35d120

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4c4cdc92-af02-418c-9e2a-700554c298afdafef216-7612-4ab2-9b6c-03cadf98f66ced6bf02d-6362-4c5c-ae18-aba8b7abf9f0
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-70c0761d49c3bbe44615490ef7b613557bcd3ccdfa71d09d74202c114d277fb7

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3bf2c74d-179c-4de6-a342-9dae169cf44e4adbc9c3-5a71-4d39-a525-54a0608219fe748f79da-6bd3-4bee-b696-daf6ff42cfc2
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8270111f4cc417bcdc58b8fcee5af06573840731d43a3d04b238435408400874

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0e9866bd-c4cf-42b8-af04-f602e6e76bec614ccc49-25db-4385-a40a-85bca6683240
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1ce1c7a1-47ef-40bf-895a-8c439aa543f61ecca799-4642-430b-b222-88cbbd60447b30f5960e-6420-4fc7-a96c-fe0241d6f3588ed3ae57-c662-4169-acbb-fc0df17b5ceddc597d69-64f0-4a5c-a2e5-a8ea5b893b13
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9dea

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5133e4f2-8d60-4a31-b146-9ca0fdf57cc1dfda519b-0bd7-438c-a143-a5fd055f82cafb46ebec-5cb1-4fef-9a7a-feb12281fe9b
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-97a1380f0ac22d5543df434518bceb2f4b47c884bd4e990396f64e72afa98acc

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2196523e-f01d-4c5f-9768-e2daa4787055344c4fae-2c5f-408e-bc2c-c2b1112cb83077654503-c1f1-4ed2-9f2a-4fabd1a06b20
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-9ff3bc0adcc5343851d69d4a833815e08f0c8d24134495b38f50fdf38d2f17b2

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
627c72f6-ce4f-46cd-9e4f-525eb203cc45f29f7729-139e-4b08-8a42-b5f75767142f
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
343bd7da-3975-44ac-be37-6a32c293491b425bde75-c72f-43dd-b20a-172a7850fda4e6e85d52-8905-47f0-9401-43a2f47d1506
Mapping establishedEvidence supported

vendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-bd4950335ff1f3f03b9dd6fa5c596f7c67c9ea6d150272de074ec3767af3532a

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
25efe013-37ba-4add-8301-bf6b1e9673ea3e3e44fc-734d-4bf5-8519-d28a60185cceac727239-9540-488e-a8eb-98df3a48f5a2ae90c36f-1f18-4d18-8f27-89772e48970e
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-c09e1a6c06a60f75d4f5a3a91108bcb8e8b7418b4d0bcbe56608e9eba3cd934b

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3b41b269-2303-47ca-9cbc-e432e5d2d3d8721a5ea5-a054-4625-85b5-9190e6744cc3a0f50ca6-7fb1-4466-886a-8e41d55a8613a5df7153-64c4-410b-8eb8-da7808b06ac1e1beccf6-0b33-4d5a-9fcf-0cd585ab6724
Mapping establishedEvidence supported

vendor-f98e1750e4b030e2bb71130d14421ff255427227a8b696c92978cf6c77fc265d · product-c27aedc6088fe47e75f3a72d532ce7dcfb4a151fd6deaeecc763cf1d10026925

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
003405fd-a521-45d5-93ef-f832c8cd2df3
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5606c4d9-22c0-48ec-a102-8bb1ae89600f
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d22fc88b6b85afc426c8220428110aecfb39a59d3b7ddf5757cf39cb9f5feb2f

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5b4570e8-0137-4eb4-b905-448254189088a4da1fe1-0059-4d16-9ac4-9cf17ceaeb19
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5ae

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
46dc6846-1e5d-4ddd-ac15-6243db7f926a49f989b6-1ec5-4267-8ab7-2884a66644ce90155fb3-fb5d-4366-a57d-29020d5356ea
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0b

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0ec09b77-7086-4091-a0ad-22f7401badc64a4dbf97-fb06-4cf1-8681-0fe07d6d876882a4acac-1ad6-4945-92d3-90860b273470
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fd0893ef7253031c8ee72effb6fcc65181f9b3f5e01f8f48b6a6ab89a31380a9

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ca9b08a8-2434-4a4e-ae79-eb1056eef2dfd3b29f26-e889-4bbc-8987-e411d1672b56db798f67-9073-47ec-a53e-8dfc9613f363
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
82771e16-73d8-41fc-8fa3-07a3d764127f

Assessments

CVSS by origin

5.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:N/I:P/A:N
5.3
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
5.3
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Direct CVE/CNA normalized decisions

5.3Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Validation
Valid match
Recomputed
5.3
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.